Shadow IT: Personal GitHub Repos Expose Employee Cloud Secrets
ID: 575d3814-d390-5d46-8fbe-2bcf85b2c463
STIX ID: report--575d3814-d390-5d46-8fbe-2bcf85b2c463
Feed Name: HackRead
**Executive Summary:** Researchers discovered that personal GitHub repositories belonging to employees at Microsoft, Red Hat, and Tigera accidentally exposed cloud credentials (including a privileged Azure Container Registry token) that could permit downloading, uploading, or overwriting private container images and enable supply-chain or runtime compromise; vendors invalidated the tokens and remediated the issues, and the report calls for scanning, least-privilege scoped keys, and secret rotation to mitigate shadow IT risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
