News29 July 2026

Uncloaked: A Misconfigured Cloud Server, a SharePoint Zero-Day, and 29 Million Leaked Secrets

Uncloaked: A Misconfigured Cloud Server, a SharePoint Zero-Day, and 29 Million Leaked Secrets

Uncloaked: A Misconfigured Cloud Server, a SharePoint Zero-Day, and 29 Million Leaked Secrets

Four stories from the last few weeks, none of them sophisticated attacks. A server nobody locked down, a webpage nobody double-checked, a patch that didn't arrive fast enough, and a number that keeps climbing every year.

1. A misconfigured Nextcloud instance exposed 367,000 files

In early July 2026, researchers found a Nextcloud deployment, the popular self-hosted file storage and collaboration platform, misconfigured in a way that left roughly 8GB of customer data, spanning 367,000 files, openly accessible. No credential theft, no exploit chain, the storage layer itself was reachable without authentication.

Why it matters: this is the same failure pattern behind the Supabase incidents we covered a few weeks ago, a storage or database layer that ships secure by default in theory, left open in practice because nobody explicitly locked it down before going live. The platform changes, the mistake doesn't. Decloak's platform layer checks for exactly this kind of open storage exposure across the services it recognises.

2. A Salesforce-hosted webpage misconfiguration exposed 13.5 million email addresses

McGraw Hill disclosed a breach traced back to a misconfigured Salesforce-hosted webpage. Have I Been Pwned's dataset confirmation lists 13.5 million unique email addresses tied to the incident, alongside names, phone numbers, and some physical addresses, drawn from more than 100GB of data that ended up publicly distributed. McGraw Hill stated the incident didn't involve Social Security numbers, financial data, or their core courseware and student platforms, but the scale of what did leak is still substantial.

Why it matters: the phrase doing the heavy lifting here is "webpage misconfiguration," not "hack." A page that was supposed to be internal, or supposed to have access controls that were never actually applied, was simply reachable. This is precisely the class of finding a security scan catches before launch, not after 13.5 million email addresses are sitting on a breach forum.

3. A critical SharePoint zero-day is being exploited faster than organisations can patch

CISA added a newly disclosed, critical Microsoft SharePoint Server vulnerability, CVE-2026-58644, CVSS 9.8, to its Known Exploited Vulnerabilities list after confirming active exploitation began almost immediately following disclosure. Federal agencies were given until July 19 to patch. For everyone else running on-premises SharePoint, the exploitation window opened the same week the fix became available.

Why it matters: the gap between "a patch exists" and "attackers are using the vulnerability it fixes" keeps shrinking. Waiting for a quiet moment to schedule an update is no longer a safe assumption for critical CVSS 9+ findings, particularly on internet-facing software. Decloak's CVE detection layer checks known software versions against actively exploited vulnerabilities like this one as part of every scan.

4. The numbers behind why hardcoded secrets keep showing up everywhere

GitGuardian's State of Secrets Sprawl 2026 report landed with a headline figure worth sitting with: 28.65 million hardcoded secrets were pushed to public GitHub repositories in 2025, a 34% increase on the year before, and the largest single-year jump the report has recorded. AI-assisted commits leaked secrets at roughly twice the baseline rate, and credentials for AI services specifically surged 81% year over year. Perhaps the most telling number: 64% of secrets leaked back in 2022 were still active and usable in January 2026. Almost nobody goes back and revokes what they've already lost.

Why it matters: we wrote a full breakdown of this exact problem, including a real $82,000 cloud bill from a single exposed key, on the Journal this week. It's worth reading alongside this digest since the two stories above (Nextcloud, Salesforce) and this one share the same root cause: something that should have required deliberate access ended up reachable by default, and nobody checked before it mattered.

The thread connecting all four

None of these needed a sophisticated attacker. A storage layer nobody locked down. A webpage nobody double-checked. A patch that shipped a little too late relative to how fast exploitation started. Millions of credentials that nobody circled back to revoke. The common failure isn't a lack of security tooling, it's the gap between "this was configured once" and "this got checked again before it mattered."


Sources: Privacy Guides on the Nextcloud misconfiguration · BrightDefense on the McGraw Hill/Salesforce breach · Cybersecurity News on CVE-2026-58644 · GitGuardian's State of Secrets Sprawl 2026

Decloak checks for open storage exposure, known CVEs, and hardcoded secrets automatically, alongside five other attack surfaces, in a free 15-second scan. Scan your site free →