<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Bank.in on Cashless Watch</title><link>http://watch.cashlessconsumer.in/tags/bank.in/</link><description>Recent content in Bank.in on Cashless Watch</description><image><title>Cashless Watch</title><url>https://watch.cashlessconsumer.in/cover.png</url><link>https://watch.cashlessconsumer.in/cover.png</link></image><generator>Hugo -- 0.146.5</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 12:30:00 +0530</lastBuildDate><atom:link href="http://watch.cashlessconsumer.in/tags/bank.in/index.xml" rel="self" type="application/rss+xml"/><item><title>India's .bank.in Domains Are Leaking Secrets — And It Shouldn't Be This Easy</title><link>http://watch.cashlessconsumer.in/posts/2026-08-19-bank-in-domains-leaking-secrets/</link><pubDate>Wed, 19 Aug 2026 12:30:00 +0530</pubDate><guid>http://watch.cashlessconsumer.in/posts/2026-08-19-bank-in-domains-leaking-secrets/</guid><description>A systematic scan of 1,393 .bank.in domains reveals env files, Spring Boot actuator endpoints, phpinfo pages, composer.json, and Laravel logs exposed in plain sight — no authentication bypass, just GET requests.</description></item></channel></rss>