STORY · PRODUKTER_

Security camera exposed GitHub admin token in login page

A security researcher discovered that firmware in a Hanwha security camera exposed a GitHub admin token directly in the login code that customers could read. The token granted full access to the organization's private repositories and could have been used to alter code or steal sensitive data.

WHY IT MATTERS

This illustrates how hardware manufacturers embed surprisingly poor practices in IoT devices, and shows that vulnerabilities in supply chain equipment can give attackers direct access to critical infrastructure and source code.

SOURCES

MACHINE-GENERATED SUMMARY This summary is written by machine from the sources below. We sort and explain — but we are a way into the field, not the final word. Check the source when something matters to you.