<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Secrets-Exposure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/secrets-exposure/</link><description>Recent content in Secrets-Exposure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/secrets-exposure/index.xml" rel="self" type="application/rss+xml"/><item><title>321 Live n8n Instances Exposed via API Tokens in Public GitHub Repos</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-leaked-n8n-api-tokens-exposed-live-instances-to-credential-t/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-leaked-n8n-api-tokens-exposed-live-instances-to-credential-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If your org runs n8n, scan your GitHub repos immediately for exposed API tokens using GitGuardian or truffleHog, then rotate any identified credentials and review what downstream integrations those tokens had access to.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The four documented abuse paths (credential pivoting via workflow API) are worth translating into detection queries for anomalous n8n API calls; build coverage for unexpected data exfiltration from workflow automation platforms this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This research illustrates how workflow-automation tools become credential aggregators — a useful data point for a secrets-management policy review, but no same-week leadership action is indicated unless n8n is confirmed in use with public-facing repos.&lt;/li>
&lt;/ul></description></item><item><title>Spring Boot /actuator/heapdump endpoint exposes secrets in memory</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-java-spring-boot-heapdump-scans-mon-jul-27th/</link><pubDate>Mon, 27 Jul 2026 13:44:31 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-java-spring-boot-heapdump-scans-mon-jul-27th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Audit all Spring Boot deployments for exposed /actuator/heapdump endpoints — this endpoint leaks in-memory secrets including API keys and DB credentials. Disable or restrict actuator endpoints via Spring Security configuration if not required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build a detection for inbound GET requests to /actuator/heapdump in web/proxy logs; active scanning activity means attackers are already probing for this endpoint in your estate.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>