Weekly briefing No. 39 published 26 Sep 2026
Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns
Reference · Patterns

Patterns

The openings we find most often from outside, each with why it matters, a check anyone can run and the direction of the fix.

Patterns 14By LeakTrace

Credential exposure

Credentials in monitored breach databases reused on production login
Employee credentials appearing in monitored breach databases are still active on the corporate SSO or VPN, giving attackers a direct password-spray path.
Critical

Infrastructure

Application admin panel exposed to the public internet
A CMS or application admin login page (WordPress, Django, phpMyAdmin, GitLab, custom SaaS) is reachable from any IP without authentication gating, IP allowlisting, or VPN.
High
Public TLS certificate approaching expiry without automated renewal
A production-facing TLS certificate is within the browser warning window and shows no evidence of ACME/auto-renewal, risking a hard outage and browser trust warnings.
Medium
Subdomain takeover risk on abandoned CNAME
A DNS CNAME record points to a third-party service (Heroku, S3, GitHub Pages, Zendesk, etc.) that no longer claims the subdomain, allowing anyone to register it and impersonate the parent domain.
High

Email authentication

DKIM signing absent on the primary mail sender
A domain's outbound mail is not cryptographically signed, so receivers cannot verify integrity or authenticity beyond IP-based SPF.
Medium
SPF configured without DMARC alignment
A domain publishes an SPF record but no DMARC policy, leaving receivers with no instruction on how to handle unauthenticated mail.
High

Supply chain

Unmaintained marketing vendor with historical corporate data access
A marketing, analytics, or engagement vendor that once had customer or employee data access remains contracted (paying) or connected (integration live), despite no active use, extending the exposure surface.
Medium

Cloud misconfiguration

S3 bucket permissions allowing anonymous list
A production or backup S3 bucket is configured to allow anonymous LIST operations, exposing the object inventory (and often the object contents) to any unauthenticated caller.
High

Insider threat

Departed employee retains SSO or SaaS access post-departure
A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.
High

Phishing infrastructure

Lookalike domain registered against the corporate brand
A recently-registered domain uses a visual or typographical variation of the corporate name (typo-squat, IDN homograph, tenant-suffix squat) and is likely being staged for wire-fraud pretext.
High

Paste site leak

Executive email addresses harvested from paste sites
Public paste-site archives contain executive email addresses paired with breached passwords, providing an off-the-shelf target list for BEC.
High

Code / repository leak

API keys committed to public GitHub repositories
Employee or contractor GitHub accounts host public repositories containing plaintext API keys, cloud credentials, or database connection strings for the corporate tenant.
Critical
Exposed .git directory on a production web server
A production web server exposes its `.git/` directory over HTTP, allowing anyone to reconstruct the full source tree, including secrets committed to history.
Critical

Third-party / vendor risk

Outside adviser with no DMARC on its sending domain
A firm’s accountant, lawyer or broker sends mail from a domain with no DMARC policy, so email in that adviser’s name can be forged to ask the firm for a payment.
Critical

See what is open from outside before anyone else does. Check my firm →