Security firm gained admin access to Baseten's GitHub in under 30 minutes
Cybersecurity firm Strix AI disclosed a vulnerability that allowed them to obtain administrative access to Baseten's production GitHub repository in just 25 minutes. The attack vector involved a exposed GitHub Personal Access Token (PAT) found through the Harbor container registry. The finding was responsibly disclosed and documented on Strix AI's blog. The incident highlights risks associated with misconfigured container registries leaking sensitive credentials. It serves as a reminder for organizations to audit third-party tooling for inadvertent secret exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in