logo

Employee Personal GitHub Repos Expose Internal Azure and Red Hat Secrets

ID: bd96b1d0-eafc-52b3-9df5-0ce44859fec2

STIX ID: report--bd96b1d0-eafc-52b3-9df5-0ce44859fec2

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-04-26

...
...

Aqua's research found that employees' personal public GitHub repositories often contain exposed Kubernetes secrets and container registry tokens, which in several cases granted pull and push access to internal registries at Microsoft, Red Hat, Tigera and others—creating a significant supply-chain and data-leak risk; the issues were reported and tokens revoked, and the report recommends scanning, least-privilege scoped keys, secret expiration, anomaly detection, and encrypted secrets tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.