Silver Leaf Technologies' Worksnaps client was found to contain hardcoded cloud credentials that exposed the company's production environment, a flaw tracked as CVE-2025-10560 and rated critical. Security researchers reported that affected client versions before 1.6.20260201 embedded AWS access keys, S3 bucket names, and related cloud access details in application binaries, allowing anyone who obtained the software to extract the secrets. The disclosed credentials reportedly authenticated as the vendor's AWS root identity, enabling access to production resources including S3 buckets that stored sensitive user data such as screenshots of employee desktops.
SEC Consult said the issue extended beyond the initial embedded keys: after the vendor removed the original hardcoded root credentials, the client still received decryptable AWS credentials from the server during login, leaving access to screenshot buckets effectively unresolved for a period. Researchers also noted additional hardcoded UCloud credentials, though their validity was not confirmed. Worksnaps has since released 1.6.20260201 as the fixed version, while recommended response actions include immediate credential rotation, restricting or removing sensitive data from exposed buckets, and upgrading all affected clients.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-18, SEC Consult publicly disclosed CVE-2025-10560, describing hardcoded cloud credentials in Worksnaps client binaries that exposed production AWS resources and sensitive S3-hosted screenshot data.
Worksnaps version 1.6.20260201 was identified as the fixed release for CVE-2025-10560, addressing the hardcoded cloud credential exposure in earlier client versions.
TypeBot addressed CVE-2026-48768 in version 3.17.0, which fixed the unsanitized fileName handling and related upload control weaknesses described in the advisory.
On 2026-06-17, CVE-2026-48768 was published for TypeBot, describing an unauthenticated arbitrary S3 object write flaw in the generate-upload-url endpoint affecting version 3.16.1 and earlier.
On 2025-07-17, SEC Consult reported to Silver Leaf Technologies that the Worksnaps Windows client contained hardcoded AWS credentials providing root-level access to the vendor's production cloud environment.
Silver Leaf Technologies later introduced additional mitigations, including pre-signed PUT URLs and server-side changes, to address the exposed cloud access issue in Worksnaps.
After the initial report, Silver Leaf Technologies updated the Worksnaps client to remove the originally embedded AWS root credentials. SEC Consult found, however, that the client still obtained decryptable AWS credentials from the server during login, so access to screenshot buckets remained possible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.