logo

Home Depot exposed access to internal systems for a year, says researcher

ID: 02745589-e690-54c1-8655-a0b7dec86892

STIX ID: report--02745589-e690-54c1-8655-a0b7dec86892

Feed Name: TechCrunch Security News

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

A security researcher found a Home Depot employee's GitHub access token exposed online (likely published by mistake) and discovered it granted access to hundreds of private repositories and cloud infrastructure including order fulfillment and inventory systems. The researcher’s private notifications to Home Depot went unanswered; TechCrunch’s outreach led to the token being revoked. The report does not provide evidence that the token was used maliciously while exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.