Threat Brief — 2026-08-24 — Exposed secrets, expired domains
Two distinct credential-exposure vectors dominate today: 28,000 servers with abandoned .git folders are leaking live AWS and Stripe keys, and a South Korean government-backed startup platform bundled its encryption key directly into an API. Separately, Infoblox reports a $7 million buying spree of expired domains—attackers are weaponising their inherited reputation, backlinks, and residual traffic for phishing and malware delivery. Microsoft also confirmed that August Patch Tuesday updates break printing and PDF export in WPF apps.
Top items
- 28,000 servers with exposed
.gitfolders leak live AWS and Stripe keys. Forgotten Git repositories on public-facing servers are exposing secrets including AWS credentials and Stripe API keys. This is a repeat of the pattern seen earlier this week with leaked AWS keys granting full corporate account control—admins must scan for and remove.gitdirectories from web roots and rotate any exposed secrets immediately. (src: securitylab-ru)
- WordlistLoader delivers Amatera via ClickFix; SynkLoader adds password-phishing capability. Gen Digital researchers identified two new malware families: WordlistLoader (a loader using ClickFix social engineering to deliver the Amatera payload) and SynkLoader (which phishes Windows passwords). SynkLoader was first reported 2026-08-21 as a Microsoft Teams phishing campaign; this finding adds WordlistLoader and Amatera as new components and the ClickFix delivery vector. Both families are believed to sell access to ransomware groups. (src: thehackernews)
- Attackers spent ~$7M acquiring expired domains to weaponise inherited trust. Infoblox warns that threat actors are mass-purchasing expired domains—retaining their DNS reputation, organic traffic, and backlinks—to use in phishing, C2, and malware infrastructure. The scale ($7M) and systematic nature suggest organised campaigns building out resilient delivery infrastructure. (src: xakep)
- South Korean startup platform breach exposes key management failures. A breach at a government-backed South Korean startup platform exposed encrypted personal data because the encryption key was embedded in a public-facing API. This is a textbook separation-of-duties failure: keys stored alongside the data they protect defeat encryption entirely. (src: bleepingcomputer)
- Microsoft Teams now lets admins automatically block external bots from meetings. A new Teams meeting protection policy allows administrators to block all identified external bots from joining meetings. This is a timely defensive control given that SynkLoader and other malware families actively abuse Teams for phishing and payload delivery. (src: bleepingcomputer)
- Microsoft confirms August Patch Tuesday breaks printing and PDF export in WPF apps. .NET Framework updates released this month are causing printing and PDF export failures in WPF applications. If your environment depends on WPF-based document workflows, hold or test these updates before broad deployment. (src: bleepingcomputer)
- BLACKNET-00 sold fake power-plant hacking software—primitive XOR disguised as SCADA exploit tool. A threat actor marketed what it claimed was industrial control system hacking software, but the actual code was a trivial XOR-based tool with no real OT capability. The scam highlights that buyers on underground markets face the same trust problems as legitimate software consumers. (src: securitylab-ru)
Themes
Secrets keep leaking through admin negligence. Today's .git folder exposure (28K servers) and the South Korean API key incident both stem from the same root cause: credentials left where attackers can find them. This echoes the leaked AWS keys story from August 21. The fix is the same—separate keys from data, scan web roots, and rotate.
Expired infrastructure as an attack surface. The $7M expired-domain campaign and the "Zombie Card" relay attack (first reported August 20) both exploit abandoned but still-functional systems. Attackers are systematically harvesting residual trust from expired domains and expired payment cards—both require no zero-day, just opportunism.
Microsoft's patch month brings operational pain alongside security fixes. Between broken WPF printing/PDF export and the ongoing Windows gaming/RGB crashes (first reported August 21), August's updates are generating enough collateral damage to warrant staged rollout policies.
