Hackers ramp up scans for leaked Git tokens and secrets
ID: 7ffab828-75d3-5d57-b88b-eaf93f0c0d77
STIX ID: report--7ffab828-75d3-5d57-b88b-eaf93f0c0d77
Feed Name: Bleeping Computer
GreyNoise observed a major spike in internet-wide scanning for exposed Git configuration files on April 20–21, 2025 — nearly 4,800 unique IPs daily — with activity concentrated in Singapore, the U.S., Spain, Germany, the UK, and India. Such scans hunt for .git/config files that can contain credentials and tokens; past operations (e.g., EmeraldWhale) used the same technique to steal thousands of cloud credentials and enabled breaches like the Internet Archive compromise, so organizations should block access to .git directories, monitor logs for suspicious access, and rotate any exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
