logo

A mishandled GitHub token exposed Mercedes-Benz source code

ID: 604a8bb5-26a4-5752-af52-785b0ab532dd

STIX ID: report--604a8bb5-26a4-5752-af52-785b0ab532dd

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-01-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A publicly posted GitHub token belonging to a Mercedes‑Benz employee granted access to internal GitHub Enterprise repositories, potentially exposing source code, API keys, DB connection strings and other sensitive internal artifacts; RedHunt Labs discovered the token, reported it (with TechCrunch assistance) and Mercedes-Benz revoked the token after being notified, stating limited repository exposure and no evidence of customer data being affected, but no public confirmation of misuse has been provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.