A public-code secret hunt found exposed n8n API tokens that could open live instances and, in some deployments, reach sensitive data and downstream credentials without a software exploit.
A critical authorization bug in Gitea raises a familiar but dangerous question: what happens when a token that should stay on the public side of the fence can still touch private branches and CI workflows?
AI agents can stitch together harmless-looking permissions into a harmful outcome unless authorization, delegation, and audit are enforced at the moment each action happens.
Qilin’s publication of Rossum Integration shows how ransomware crews use victim listings as pressure, while the real technical risk may sit inside document workflows, credentials, and downstream finance systems.