28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
ID: eadf29b2-1d31-5c8c-9bf5-35f7e4897f7e
STIX ID: report--eadf29b2-1d31-5c8c-9bf5-35f7e4897f7e
Feed Name: GBHackers
A security research scan of 3.5 million live HTTP hosts found 28,000 exposed .git repositories that leaked credentials (including AWS, Stripe, OpenAI and GitHub tokens) by allowing external access to Git metadata; Intruder used an in-memory Git object walker (gitreaper) to extract historical commits and discovered hundreds of active keys with potential access to sensitive data and services, and recommends blocking .git access, rotating credentials, auditing full Git history, and adding automated secret scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
