logo

Exposed Git Repositories Leak Critical Cloud Secrets

ID: 44ed3d27-ef6f-5ddd-91a5-16a9336b37c3

STIX ID: report--44ed3d27-ef6f-5ddd-91a5-16a9336b37c3

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Do Son

...
...

Security researchers discovered that thousands of publicly accessible .git directories exposed sensitive credentials and internal records across 28,000 repositories on 3.5 million scanned hosts; recovered secrets included hundreds of live AWS keys, Stripe secret keys, OpenAI keys, Telegram tokens, and GitHub personal access tokens, risking cloud takeover and data theft. The report attributes the issue to basic web server misconfiguration, describes an open-source scanning tool (gitreaper) used to recover secrets from commit history, and urges immediate remediation: block public access to .git, rotate exposed keys, and add automated secret scanning to CI pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.