HomeSecurity OperationsExposed Git Tokens and Secrets Being Targeted by Hacker Scans

Exposed Git Tokens and Secrets Being Targeted by Hacker Scans

Published on

spot_img

  • GreyNoise observed a notable surge in scanning activities.
  • IPs originating from Singapore are searching for exposed Git configuration files, predominantly within Singapore’s digital landscape.
  • The compromised files may contain sensitive information, including login credentials and access tokens.

Cybersecurity researchers from GreyNoise have highlighted a concerning trend in Singapore, where local threat actors appear to be actively targeting organizations for potential exploitation. In a recent analysis, the firm reported a substantial uptick in reconnaissance activities indicative of cyber exploitation attempts.

On April 20-21, GreyNoise recorded an alarming increase in the number of unique IP addresses engaged in scanning for exposed Git configuration files. The statistics revealed a staggering 4,800 unique IP addresses implicated in this activity during just those two days—a marked increase compared to typical scanning levels.

While the majority of these IPs were located in Singapore, GreyNoise noted that several came from countries such as the United States, Germany, the United Kingdom, and the Netherlands. The scanners were predominantly focused on networks within Singapore but extended their efforts to other countries, including the US, UK, Germany, and India.

Source link

Latest articles

Anthropic Tests Claude Money for Bank Data Analysis

Anthropic Expands AI Capabilities with Launch of Claude Money: A Look at Its Financial...

JADEPUFFER Enhances Agentic Ransomware to Focus on AI Models and Training Data

Evolution of the JADEPUFFER Threat: Targeting AI and Machine Learning Assets The cybersecurity landscape is...

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...

PowerShell Malware Exploits Registry and DNS TXT Records for XMRig Crypto Miner Deployment

A sophisticated cryptomining campaign has recently come to light, employing intricate layers of obfuscation...

More like this

Anthropic Tests Claude Money for Bank Data Analysis

Anthropic Expands AI Capabilities with Launch of Claude Money: A Look at Its Financial...

JADEPUFFER Enhances Agentic Ransomware to Focus on AI Models and Training Data

Evolution of the JADEPUFFER Threat: Targeting AI and Machine Learning Assets The cybersecurity landscape is...

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...