Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
leaked-secret-api-keycloud-service-vulnerabilitywidely-deployed-product-advisorycloud-misconfiguration

Hardcoded AWS Root Credentials in Worksnaps Client Exposed Production S3 Data

Updated 2d agoFirst seen Jun 18, 20263 sources

Silver Leaf Technologies' Worksnaps client was found to contain hardcoded cloud credentials that exposed the company's production environment, a flaw tracked as CVE-2025-10560 and rated critical. Security researchers reported that affected client versions before 1.6.20260201 embedded AWS access keys, S3 bucket names, and related cloud access details in application binaries, allowing anyone who obtained the software to extract the secrets. The disclosed credentials reportedly authenticated as the vendor's AWS root identity, enabling access to production resources including S3 buckets that stored sensitive user data such as screenshots of employee desktops.

SEC Consult said the issue extended beyond the initial embedded keys: after the vendor removed the original hardcoded root credentials, the client still received decryptable AWS credentials from the server during login, leaving access to screenshot buckets effectively unresolved for a period. Researchers also noted additional hardcoded UCloud credentials, though their validity was not confirmed. Worksnaps has since released 1.6.20260201 as the fixed version, while recommended response actions include immediate credential rotation, restricting or removing sensitive data from exposed buckets, and upgrading all affected clients.

Share:
Hardcoded AWS Root Credentials in Worksnaps Client Exposed Production S3 Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jun 18, 202613d ago

SEC Consult publicly discloses Worksnaps credential exposure

On 2026-06-18, SEC Consult publicly disclosed CVE-2025-10560, describing hardcoded cloud credentials in Worksnaps client binaries that exposed production AWS resources and sensitive S3-hosted screenshot data.

Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies - Worksnaps.net Worksnaps

Worksnaps fix released in version 1.6.20260201

Worksnaps version 1.6.20260201 was identified as the fixed release for CVE-2025-10560, addressing the hardcoded cloud credential exposure in earlier client versions.

CVE-2025-10560 - Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources
Jun 17, 202614d ago

TypeBot fixes CVE-2026-48768 in version 3.17.0

TypeBot addressed CVE-2026-48768 in version 3.17.0, which fixed the unsanitized fileName handling and related upload control weaknesses described in the advisory.

CVE-2026-48768 - TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName

TypeBot arbitrary S3 object write vulnerability is published

On 2026-06-17, CVE-2026-48768 was published for TypeBot, describing an unauthenticated arbitrary S3 object write flaw in the generate-upload-url endpoint affecting version 3.16.1 and earlier.

CVE-2026-48768 - TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName
Jul 17, 20251y ago

SEC Consult reports Worksnaps hardcoded AWS root credentials to vendor

On 2025-07-17, SEC Consult reported to Silver Leaf Technologies that the Worksnaps Windows client contained hardcoded AWS credentials providing root-level access to the vendor's production cloud environment.

Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies - Worksnaps.net Worksnaps
Dec 11, 20224y ago

Vendor implements further Worksnaps client and server-side mitigations

Silver Leaf Technologies later introduced additional mitigations, including pre-signed PUT URLs and server-side changes, to address the exposed cloud access issue in Worksnaps.

Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies - Worksnaps.net Worksnaps

Vendor removes original hardcoded root credentials from Worksnaps client

After the initial report, Silver Leaf Technologies updated the Worksnaps client to remove the originally embedded AWS root credentials. SEC Consult found, however, that the client still obtained decryptable AWS credentials from the server during login, so access to screenshot buckets remained possible.

Full Disclosure: SEC Consult SA-20260618-0 :: Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies - Worksnaps.net Worksnaps
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
3 linked
TypebotWindowsFreshdesk
Organizations
7 linked
WorksnapsSilver Leaf TechnologiesAmazon Web ServicesTypebotSEC ConsultAtosFreshworks
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.