Sploitus New Cybersecurity Tools: shhgit and PersistenceSniper Exploits
Article Content
- •Shhgit scans code repositories for sensitive information to prevent leaks.
- •PersistenceSniper automates detection of persistence methods on multiple machines.
- •Both tools are available for use, enhancing security practices.
Two new cybersecurity tools have emerged: shhgit, which helps teams find secrets in code repositories, and PersistenceSniper, designed for automated detection of persistence methods on machines. Shhgit scans public repositories for sensitive information like API tokens and credentials, aiming to prevent leaks before they occur. It operates in both public and local modes, requiring GitHub tokens for access. PersistenceSniper, on the other hand, focuses on identifying known persistence methods across multiple systems, providing a user-friendly interface for analysis. The tool is built on contributions from various researchers and aims to fill gaps left by existing tools like Sysinternals' Autoruns. Both tools are available for use, with shhgit having a live web interface option. As of now, there are no confirmed exploitation incidents associated with these tools, but they serve as preventive measures against potential leaks and unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…