← All talks

Zero Trust Security: Jira & Slack Secrets Leak Danger #shorts

BSides Frankfurt0:50236 viewsPublished 2026-04Watch on YouTube ↗
About this talk
Traditional network access is obsolete in Zero Trust. But secrets shared in Jira comments can sync to open Slack channels, leading to major breaches. A shared comment can expose sensitive data company-wide. #CyberSecurity #ZeroTrust #DataBreach #Jira #Slack
Show transcript [en]

The days of getting access to a network, firing up NetView, firing up Nmap, trying to you know, scrape the network, those days are pretty much gone. In a zero trust environment. And I this I put this up there. This was earlier this week. This tweet came up about secrets that were in a it was shared in a Jira comment, which got synchronized to Slack. Um anybody out there using Jira and Slack? They've got lovely Slack bots. So, then anytime somebody comments on an issue, that will get synchronized over to Slack to let you know, so you can see it right there. Well, maybe your Jira instance is really locked down and you have, you know, only internal people

can access it. But then all the comments get synchronized right over to an open Slack channel that anybody in the company can read or search through. And then bad things happen.