CyberHighConfirmedDeveloping
10.0
AgentForger vulnerability allows unauthorized ChatGPT Workspace Agent deployment via phishing
The Hacker News·3 days ago
Threat actors are actively scanning for and exploiting misconfigured Spring Boot applications that expose the /actuator/heapdump endpoint. This vulnerability allows unauthorized access to memory dumps containing sensitive credentials, including API keys and database passwords, posing a significant risk of lateral movement and data exfiltration.