logo

28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials

ID: eadf29b2-1d31-5c8c-9bf5-35f7e4897f7e

STIX ID: report--eadf29b2-1d31-5c8c-9bf5-35f7e4897f7e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Mayura Kathir

...
...

A security research scan of 3.5 million live HTTP hosts found 28,000 exposed .git repositories that leaked credentials (including AWS, Stripe, OpenAI and GitHub tokens) by allowing external access to Git metadata; Intruder used an in-memory Git object walker (gitreaper) to extract historical commits and discovered hundreds of active keys with potential access to sensitive data and services, and recommends blocking .git access, rotating credentials, auditing full Git history, and adding automated secret scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.