"Leaked GitHub Token Exposed Mercedes Source Code"
"Leaked GitHub Token Exposed Mercedes Source Code"
According to security researchers at RedHunt, a GitHub token leaked by a Mercedes-Benz employee provided access to all the source code stored on the carmaker’s GitHub Enterprise server. The token, discovered during an internet scan, was leaked in the employee’s GitHub repository, providing unrestricted and unmonitored access to the source code. The researchers stated that the breach occurred on September 29, 2023, but was not discovered until January 11, 2024. Mercedes revoked the leaked token on January 24, two days after being alerted of the incident.