HomeSecurity OperationsExposed Git Tokens and Secrets Being Targeted by Hacker Scans

Exposed Git Tokens and Secrets Being Targeted by Hacker Scans

Published on

spot_img

  • GreyNoise observed a notable surge in scanning activities.
  • IPs originating from Singapore are searching for exposed Git configuration files, predominantly within Singapore’s digital landscape.
  • The compromised files may contain sensitive information, including login credentials and access tokens.

Cybersecurity researchers from GreyNoise have highlighted a concerning trend in Singapore, where local threat actors appear to be actively targeting organizations for potential exploitation. In a recent analysis, the firm reported a substantial uptick in reconnaissance activities indicative of cyber exploitation attempts.

On April 20-21, GreyNoise recorded an alarming increase in the number of unique IP addresses engaged in scanning for exposed Git configuration files. The statistics revealed a staggering 4,800 unique IP addresses implicated in this activity during just those two days—a marked increase compared to typical scanning levels.

While the majority of these IPs were located in Singapore, GreyNoise noted that several came from countries such as the United States, Germany, the United Kingdom, and the Netherlands. The scanners were predominantly focused on networks within Singapore but extended their efforts to other countries, including the US, UK, Germany, and India.

Source link

Latest articles

GitHub’s 8-Hour Outage Linked to Autoscaling Failure

On August 17, GitHub experienced a significant service disruption lasting 7 hours and 47...

Webinar Announcement – Governance of AI Agents by Fortune 500 Security Teams

Transforming Security: Fortune 500 Leaders Adapt to AI Agents Organizations within the Fortune 500 are...

Zero-Click Grok Attack Enables Hackers to Steal Chat History via Encrypted Prompt Injection

New Prompt-Injection Technique Exposes Potential Vulnerabilities in AI Systems A recently revealed prompt-injection technique raises...

Meta Collects Three Times More Data Than Apple and Microsoft

A recent study conducted by the virtual private network (VPN) provider Surfshark has uncovered...

More like this

GitHub’s 8-Hour Outage Linked to Autoscaling Failure

On August 17, GitHub experienced a significant service disruption lasting 7 hours and 47...

Webinar Announcement – Governance of AI Agents by Fortune 500 Security Teams

Transforming Security: Fortune 500 Leaders Adapt to AI Agents Organizations within the Fortune 500 are...

Zero-Click Grok Attack Enables Hackers to Steal Chat History via Encrypted Prompt Injection

New Prompt-Injection Technique Exposes Potential Vulnerabilities in AI Systems A recently revealed prompt-injection technique raises...