vulnerability Java Spring Boot "heapdump" scans, (Mon, Jul 27th) A vulnerability in Spring Boot applications exposes a heapdump endpoint that, by default, contains sensitive data like API keys and database passwords. Attackers are leveraging a weak default username/password combination to gain access to these dumps, highlighting a critical security oversight in Spring Boot deploymen… SANS Internet Storm Center · Jul 27, 2026 High springheapdumpsecurity
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault