Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
A 'medium' CVSS told you to skip this one.
It is dumping live Amazon SES and OAuth keys to anyone who asks, on 100,000 WordPress sites.
Patching does not take the leaked keys back. Rotate them. (CVE-2026-4020)
https://suriq.io/blog/gravity-smtp-credential-leak-cve-2026-4020
2026-06-20T16:53:49.768Z