Nearly 5 Million Web Servers Found Exposing Git Metadata – Study Reveals Widespread Risk of Code and Credential Leaks
ID: 6040d0ef-3d78-5135-bf9f-69449ba4f0b5
STIX ID: report--6040d0ef-3d78-5135-bf9f-69449ba4f0b5
Feed Name: Security Affairs
A 2026 study by Mysterium VPN researchers found ~4.96 million public IPs exposing .git directories and ~252,733 .git/config files leaking deployment credentials (~5%), concentrated in major hosting hubs (US, Germany, France). The report warns that exposed Git metadata enables source-code reconstruction, credential theft, malicious commits, and supply-chain or cloud access, and recommends blocking .git access, removing Git data from production, rotating leaked credentials, and implementing secrets management and deployment controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
