Home Depot allegedly left internal systems at risk for over a year


  • Home Depot unveiled a GitHub token for a year, giving access to critical internal systems
  • Researchers’ warnings were ignored until the media intervened, after which the token was revoked
  • Similar leaks across GitHub/GitLab show widespread risks from hardcoded secrets and misconfigured repos

Home Depot kept access to its internal systems open for more than a year to anyone who knew where to look, experts have warned.

Security researcher Ben Zimmermann recently found a published GitHub access token that belonged to a Home Depot employee.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top