logo

Lessons from the Mercedes-Benz GitHub source code leak

ID: 6112eb37-162a-5259-ac89-374a58cf4740

STIX ID: report--6112eb37-162a-5259-ac89-374a58cf4740

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2024-02-01

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

RedHunt Labs discovered a publicly exposed GitHub access token belonging to a Mercedes‑Benz employee that granted unrestricted access to internal GitHub Enterprise repositories, potentially exposing source code, database connection strings, cloud keys, SSO passwords, API keys and other sensitive development artifacts; Mercedes revoked the token and removed the public repository after notification. The report frames this as part of a wider problem of leaked developer secrets and software supply‑chain risk, cites prior Mercedes supply‑chain exposures, and urges stronger supply‑chain security controls beyond traditional AppSec.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.