Hackers find 15,000 credentials by scanning for git configuration
ID: 98a5e926-8b0c-5020-bd14-dd4570ed8dee
STIX ID: report--98a5e926-8b0c-5020-bd14-dd4570ed8dee
Feed Name: CyberScoop
Sysdig discovered an open Amazon S3 bucket holding more than 1 TB of data attributed to an operation called EMERALDWHALE that harvested over 15,000 cloud and email service credentials by targeting exposed Git configuration files. The collected data included validated keys, access to private repositories and malicious tools; researchers observed activity from August–September and assessed the credentials are being used for spam, phishing and resale on underground markets, highlighting automated, low-effort but high-impact leakage paths from exposed repositories and configuration files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
