A routine development mistake has exposed thousands of software repositories. Researchers found 28,000 publicly reachable .git repositories containing credentials, financial information and internal employee records that could give criminals a direct route into cloud accounts and business systems. This is not a malware campaign in the usual sense. The risk begins when a web server accidentally leaves its hidden Git directory reachable, allowing automated scanners to retrieve code and earlier versions of files. A leaked secret can then be used for data theft, payment fraud, phishing or malicious code changes. Intruder analysts identified the exposure while examining internet-facing systems at scale. Intruder said in a report...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!