← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Log4j Vulnerability Alert Deemed Overblown, Minimus Shuts Down, Credential Leaks Found

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Log4j developers downplayed a recent RCE vulnerability alert.
  • Minimus, a hardened container image provider, shut down and was acquired by Echo.
  • Research found over 700 active corporate AWS keys granting full account control.
  • Thousands of other API keys and tokens were found exposed in Git repositories.

Log4j Vulnerability Clarification

A recent alert regarding a critical remote code execution (RCE) vulnerability in Apache Log4j 2 caused concern within the cybersecurity community. However, Log4j developers addressed these fears, labeling the issue a "known security non-finding." They confirmed the potential for RCE but emphasized the specific circumstances necessary for exploitation, suggesting that developer time could be better spent on other priorities. This clarification follows the significant impact of the Log4Shell flaw several years ago.

Minimus Cybersecurity Firm Shuts Down

Minimus, a provider of hardened container images, has ceased operations despite raising $51 million in 2025. The company cited the challenging business and investment climate as reasons for its inability to continue. This shutdown occurred less than a month after Minimus participated in the Black Hat conference. Shortly after the announcement, Echo acquired Minimus and its technology.

Corporate Credential Leaks Discovered

Truffle Security conducted a study that identified over 700 still-active corporate AWS keys, which provided full control over the associated accounts. This discovery was made during a review of 10,616 AWS keys exposed between 2022 and 2026. In a separate finding, Intruder scanned 3.5 million active hosts and found 28,000 exposed Git repositories. This scan uncovered more than 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub PATs. Some of these credentials remained active, potentially allowing access to cloud environments, private source code, and other sensitive systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Aug 28

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Log4j developers clarified that a recent remote code execution vulnerability alert was a "known security non-finding" requiring specific exploitation circumstances. Separately, cybersecurity firm Minimus ceased operations after raising $51 million, with its technology subsequently acquired by Echo. Research also revealed thousands of exposed and active corporate AWS and other API keys.