Postman Workspaces Leak 30000 API Keys and Sensitive Tokens
ID: 82e8a372-c7d1-536a-a8e4-f0bf27dc9824
STIX ID: report--82e8a372-c7d1-536a-a8e4-f0bf27dc9824
Feed Name: HackRead
CloudSEK’s year-long investigation found more than 30,000 public Postman workspaces leaking sensitive data—API keys, access/refresh tokens, and admin credentials—affecting organizations across sectors and exposing services such as GitHub, Slack, and Salesforce; causes include misconfigured access, plaintext secrets, and accidental public sharing, and recommended mitigations are environment variables, token rotation, and dedicated secret-management tools while Postman has begun enforcing secret-protection policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
