logo

Nearly 5 Million Web Servers Found Exposing Git Metadata – Study Reveals Widespread Risk of Code and Credential Leaks

ID: 6040d0ef-3d78-5135-bf9f-69449ba4f0b5

STIX ID: report--6040d0ef-3d78-5135-bf9f-69449ba4f0b5

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A 2026 study by Mysterium VPN researchers found ~4.96 million public IPs exposing .git directories and ~252,733 .git/config files leaking deployment credentials (~5%), concentrated in major hosting hubs (US, Germany, France). The report warns that exposed Git metadata enables source-code reconstruction, credential theft, malicious commits, and supply-chain or cloud access, and recommends blocking .git access, removing Git data from production, rotating leaked credentials, and implementing secrets management and deployment controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.