Thursday, May 15, 2025
HomeCyber Security NewsMercedes-Benz Source Code Leaked via mishandled GitHub token

Mercedes-Benz Source Code Leaked via mishandled GitHub token

Published on

SIEM as a Service

Follow Us on Google News

Mercedes-Benz has been reported to have leaked its source code due to a GitHub token leak from an organization employee.

This particular leak was identified during an internet scan from a research team, revealing a GitHub repository holding this information.

This token gave unrestricted and unmonitored access to the entire source code that was hosted on the Internal GitHub Enterprise server, which had sensitive information such as intellectual property and compromised information, including Database Connection Strings, Cloud Access Keys, Blueprints, Design Documents, SSO Passwords, API Keys, and Other Critical internal information.

- Advertisement - Google News
Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

Results if Exploited

According to the reports shared with Cyber Security News, if a threat actor had access to this token, there was a variety of sensitive information that the threat actor could use for various malicious operations.

A threat actor could have utilized this token to retrieve all the sensitive information including API keys, Cloud Access keys, etc., to steal data from Mercedes-Benz.

Further, this information could have also been sold at dark web marketplaces in exchange for bitcoins or any cryptocurrency.

Additionally, there could also be financial consequences that could have happened due to data theft, extortion, backdoor deployment, ransomware deployment, and any malicious activities that could benefit the attacker.

From a company perspective, if these data consisted of any kind of consumer information, GDPR violations could have taken place that could cause millions of dollars in loss.

On the other hand, this also spoils Mercedes-Benz’s reputation, leading to a reduction in customers’ trust followed by a loss of business.

Redhunt Labs report details the incident’s consequences, impact, risk, and other information.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Google Threat Intelligence Releases Actionable Threat Hunting Technique for Malicious .desktop Files

Google Threat Intelligence has unveiled a series of sophisticated threat hunting techniques to detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...