Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
2026-07-28T01:23:40Z•9e21844f7a7490164c166f940b8eee25edfc1cf2337571fd5b24bc31bc6a5211
ESAFENET CDGGeoServerSQL injectionSpring ActuatorSpring BootXSScredential exposureheapdump exposureinternet scanningsecret leakagethreat intelligenceweak passwords
What happened
SANS ISC reports internet scanning for exposed Java Spring Boot Actuator /actuator/heapdump endpoints, which can disclose heap memory containing API keys, database passwords, and other application secrets. It also notes scanning targeting ESAFENET CDG document management systems with weak logins and previously reported SQL injection and XSS issues. The feed includes additional observations about Geoserver activity and autonomous attacker disclosures, but provides no specific CVE identifiers.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 9e21844f7a7490164c166f940b8eee25edfc1cf2337571fd5b24bc31bc6a5211
- Enrichment time
- 2026-07-28T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.