Threat Intelligence Weekly Report

Demo Corp | Report ID: demo_20260927 | September 27, 2026
Overall Threat Level
CRITICAL
1
Critical
2
High
3
Medium
7
Total Findings

Findings by Source

SourceFindings
domain_monitor2
reddit2
github1
paste_site1
certificate_transparency1

Detailed Findings

CRITICAL (1)

Leaked .env file with database credentials on GitHub
github | 2026-09-27T13:44:13 | Keywords: democorp, democorp.example
A public GitHub repository contains a .env file with what appears to be database credentials and API keys associated with the client domain. The repository appears to be a development fork that was made public by mistake.
View source

HIGH (2)

DNS resolution failure for democorp.example
domain_monitor | 2026-09-27T16:15:43 | Keywords: democorp.example
Domain democorp.example does not resolve in DNS. Possible takeover or configuration issue.
View source
Credential dump on Pastebin mentions client domain
paste_site | 2026-09-27T10:44:13 | Keywords: democorp.example
A paste on pastebin.com contains what appears to be a list of email addresses and password hashes. Several entries use the democorp.example domain, suggesting a potential credential leak from the organization.
View source

MEDIUM (3)

Discussion on r/cybersecurity about Demo Corp security practices
reddit | 2026-09-27T03:44:13 | Keywords: Demo Corp
A thread on r/cybersecurity discusses Demo Corp's recent security practices. The thread includes some criticism of their incident response time and mentions potential vulnerabilities in their web infrastructure.
View source
New SSL certificate issued for api.democorp.example
certificate_transparency | 2026-09-26T19:44:13 | Keywords: democorp.example
A new SSL certificate was issued for api.democorp.example via Let's Encrypt. This may be legitimate but should be verified as no corresponding deployment was announced.
View source
New subdomain detected: dev-democorp.example
domain_monitor | 2026-09-24T15:44:13 | Keywords: democorp.example
A new DNS record was detected for dev-democorp.example. This subdomain was not previously registered and resolves to an external IP address. Possible subdomain takeover risk.
View source

LOW (1)

John Demo mentioned in netsec thread about executive credentials
reddit | 2026-09-25T15:44:13 | Keywords: John Demo
A post on r/netsec mentions executive John Demo in the context of a broader discussion about credential reuse among C-suite executives. No direct credential leak identified, but the mention creates reputation risk.
View source