Mercedes-Benz data exposed; passwords, cloud access keys leaked

A GitHub token leak compromised Mercedes-Benz’s source code, revealing critical internal information including intellectual property, passwords, and cloud access keys.

The breach was traced back to a Mercedes-Benz employee’s GitHub token, found in a public repository on September 29. RedHunt Labs researchers determined that this token provided unrestricted access to the car manufacturer’s internal GitHub Enterprise Server.

Sensitive data exposed in the leak included database connection strings, cloud access keys, blueprints, design documents, single sign-on (SSO) passwords, API keys, and other vital internal details, according to the RedHunt Labs report.

Read more

You may also like

More in IT

Comments are closed.