top of page


Repo Roulette: Spin the Wheel, Win a Credential
A security researcher used automated TruffleHog scans across all 5.6 million public GitLab Cloud repositories and found 17,430 live secrets tied to 2,804 domains—including cloud, database, messaging, and OpenAI keys—showing that many organizations still expose long-lived credentials in public code despite some revocations after notification.
Dec 10, 202514 min read


Campus Lifehack: Don’t Let Your ERP Major in Compromise
Synthesizing all three sources, the OSINT indicates that an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite in August 2025 to hack the Oracle EBS environments of the University of Pennsylvania and the University of Phoenix.
Dec 4, 202517 min read
bottom of page