A disclosure flaw in Gravity SMTP turned a mail helper into a potential source of API keys, tokens, and site fingerprints, showing how small permission mistakes can create outsized exposure.
A malicious npm package exposed its operator’s private GitHub token, underscoring supply-chain risks and the dangers of exposed credentials.
A supply-chain incident did not stop at the package registry; one unrotated GitHub credential appears to have kept a door open into source repositories.
A validation bug in a PHP toolchain turned a routine authentication failure into a secrets-disclosure risk inside CI logs, showing how upstream token changes can ripple into downstream security.