Sunday 26 July 2026 11:23:05 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#token leak


One WordPress Email Plugin, One Missing Lock, and a Very Large Secret Trail

Published: 18 June 2026 16:03Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A disclosure flaw in Gravity SMTP turned a mail helper into a potential source of API keys, tokens, and site fingerprints, showing how small permission mistakes can create outsized exposure.

A Package That Stole Files and Spilled Its Own GitHub Secret

Published: 28 May 2026 14:50Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A malicious npm package exposed its operator’s private GitHub token, underscoring supply-chain risks and the dangers of exposed credentials.

The Forgotten Token That Opened Grafana’s Code Vault

Published: 22 May 2026 10:14Category: Breaches & Data LeaksGeo: North America / USAAuthor: SECURERECLAIMER

A supply-chain incident did not stop at the package registry; one unrotated GitHub credential appears to have kept a door open into source repositories.

The Quiet Leak in the Build Chain: How a Token Format Change Put Composer on Alert

Published: 14 May 2026 10:38Category: Cloud, SaaS & Identity SecurityGeo: Europe / GermanyAuthor: SHADOWFIREWALL

A validation bug in a PHP toolchain turned a routine authentication failure into a secrets-disclosure risk inside CI logs, showing how upstream token changes can ripple into downstream security.