CVE-2025-10560Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 106-1806-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-181
Disclosure1
2026-06-191
General1
Full discourse2 posts
  • Autumn Good@autumn_good_35
    Disclosure

    『Hardcoded AWS cloud credentials in the Worksnaps client gave an attacker complete access the Worksnaps AWS infrastructure as AWS root account』 CVE-2025-10560 Hardcoded Root Cloud Credentials in Application Binaries in Silver Leaf Technologies Worksnaps https://sec-consult.com/vulnerability-lab/advisory/hardcoded-root-cloud-credentials-in-application-binaries-in-silver-leaf-technologies-worksnaps/

    Post summary

    The advisory discloses that hardcoded AWS credentials in the Worksnaps client allow root-level access to the vendor's AWS infrastructure.

    01010316
    6.9K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    General

    CVE-2025-10560 (Worksnaps client) is a critical hard-coded credentials flaw exposing AWS. Extracted credentials could allow access to production cloud resources. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-18/TIER_2_CVE-2025-10560.md #CyberSecurity #CloudSecurity #DPI #SecretsManagement #DigitalIdentity

    Post summary

    The post points to CVE‑2025‑10560 as a hard‑coded credential flaw that could expose AWS resources, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000033
    53 followersView on X

Explore more