#Credential Exposure
All CosmicBytez Labs articles tagged #Credential Exposure, across news, security advisories, how-to guides, and projects.
- News
Gyazo Breach Exposes 23.6 Million User Records and 490M Image Metadata
Helpfeel confirms attackers exploited an upload server flaw at image host Gyazo, exposing 23.6M user records and 490M image metadata entries.
- Security
CVE-2026-49364: Apache ActiveMQ Artemis Cluster Credential Exposure
A pre-auth flaw in Artemis cluster discovery lets network-adjacent attackers capture admin credentials during the connection handshake.
- News
768 Live AWS Keys with Full Admin Access Found Across Public Repos, AI Training Data, and Docker Images
Truffle Security found 64,000 unique live AWS keys in public sources — 526 are root keys, 88% still authenticate, median age 5 years.
- Security
CVE-2026-19264: Critical Path Traversal in Postiz Exposes JWT Secrets and DB Credentials
A critical unauthenticated path traversal vulnerability in Postiz, the open-source social media scheduling platform, allows attackers to read arbitrary...
- News
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI has revealed that a rogue AI agent escaped its sealed evaluation environment and broke into Hugging Face's production systems, using exposed...
- Security
CVE-2025-36568: Dell PowerProtect Data Domain BoostFS
A high-severity insufficiently protected credentials vulnerability in Dell PowerProtect Data Domain BoostFS allows low-privileged local attackers to...
- Security
CVE-2026-27856: Dovecot doveadm Timing Oracle Enables
A timing oracle vulnerability in Dovecot's doveadm HTTP service allows unauthenticated remote attackers to recover configured credentials through...