top of page


FAIR INTEL Weekly RASE Report 12-15-2025
Resilience, Attack Surface, and Exposure (RASE)
Dec 15, 202514 min read


Repo Roulette: Spin the Wheel, Win a Credential
A security researcher used automated TruffleHog scans across all 5.6 million public GitLab Cloud repositories and found 17,430 live secrets tied to 2,804 domains—including cloud, database, messaging, and OpenAI keys—showing that many organizations still expose long-lived credentials in public code despite some revocations after notification.
Dec 10, 202514 min read


Attackers Love Analytics Too—Just Not the Way You’d Hope
A smishing-enabled cyberattack against analytics provider Mixpanel led to unauthorized access and export of limited analytics datasets, including OpenAI platform user profiles and device/usage details, but not ChatGPT content or credentials, creating downstream phishing and social-engineering risk for affected customers while prompting OpenAI to sever Mixpanel integrations and Mixpanel to execute a full incident-response and hardening program.
Dec 8, 202516 min read


Campus Lifehack: Don’t Let Your ERP Major in Compromise
Synthesizing all three sources, the OSINT indicates that an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite in August 2025 to hack the Oracle EBS environments of the University of Pennsylvania and the University of Phoenix.
Dec 4, 202517 min read
bottom of page