Close Menu
Bangla news
  • Home
  • Bangladesh
  • Business
  • International
  • Entertainment
  • Sports
  • বাংলা
Facebook X (Twitter) Instagram
Bangla news
  • Home
  • Bangladesh
  • Business
  • International
  • Entertainment
  • Sports
  • বাংলা
Bangla news
Home Home Depot Data Breach Risk: Exposed GitHub Token Ignored for Weeks
Business Desk
Brand's Information Business Ecommerce & Shopping English Technology

Home Depot Data Breach Risk: Exposed GitHub Token Ignored for Weeks

Business DeskarjuDecember 13, 20253 Mins Read
Advertisement

A major security lapse at Home Depot put internal systems at risk for nearly a year. A researcher found a private company access token posted publicly online. The token granted deep access to Home Depot’s digital infrastructure.The issue began in early 2024. It remained unaddressed until media inquiry in December 2025. According to TechCrunch, the company initially ignored the researcher’s warnings.

Researcher Finds Unprotected Key to Internal Systems

Security expert Ben Zimmermann discovered the token in early November. It was a GitHub access token belonging to a Home Depot employee. The token was likely published by mistake.Testing confirmed its power. The key provided access to hundreds of private Home Depot source code repositories. It even allowed modifications to that code.This access was extensive. It included cloud infrastructure, order fulfillment, and inventory management systems. Development pipelines were also exposed.Home Depot has relied on GitHub for engineering since 2015. This made the exposure particularly dangerous. A malicious actor could have caused significant harm.

Home Depot Data Breach Risk: Exposed GitHub Token Ignored for Weeks

Failed Disclosure Leads to Media Intervention

Zimmermann attempted to report the flaw responsibly. He sent multiple emails to Home Depot security contacts. He received no response for weeks.He also messaged the company’s chief information security officer on LinkedIn. That attempt also failed. The researcher had successfully reported similar issues to other firms.”Home Depot is the only company that ignored me,” Zimmermann stated. The company lacks a formal bug bounty program. This made responsible disclosure difficult.Frustrated, the researcher contacted TechCrunch. The news outlet reached out to Home Depot on December 5. The token was revoked shortly after that contact.It remains unclear if anyone else used the token maliciously. Home Depot did not comment on whether they reviewed access logs. The company spokesperson acknowledged receipt but did not answer follow-up questions.

US Sanctions Maduro Nephews as Tensions Rise Over Migrant Flight Suspension

This Home Depot data breach risk highlights critical gaps in corporate security response. The company’s systems are now secure, but the delayed fix raises serious questions.

Thought you’d like to know

Q1: What was exposed in the Home Depot security incident?

The exposed item was a GitHub access token. This digital key granted access to private company source code and internal systems. It could modify code for order and inventory systems.

Q2: How long was the Home Depot token exposed online?

The token was publicly available for nearly a full year. It was posted in early 2024 and discovered in November 2025. The exposure lasted until early December 2025.

Q3: Did Home Depot know about the problem before the media?

Yes. A security researcher alerted the company weeks before TechCrunch’s report. Home Depot did not respond to multiple private disclosure attempts from the finder.

Q4: What could a hacker have done with the exposed token?

A bad actor could have accessed and altered internal software. This includes systems managing orders and warehouse inventory. The access was broad and potentially very damaging.

Q5: Has Home Depot fixed the security flaw?

Yes. The token was revoked shortly after TechCrunch contacted the company. The public exposure point is now closed, according to the researcher’s findings.


iNews covers the latest and most impactful stories across entertainment, business, sports, politics, and technology, from AI breakthroughs to major global developments. Stay updated with the trends shaping our world. For news tips, editorial feedback, or professional inquiries, please email us at [email protected].

Get the latest news and Breaking News first by following us on Google News, Twitter, Facebook, Telegram , and subscribe to our YouTube channel.

brands breach business data depot ecommerce english exposed: for github home ignored information risk shopping technology token weeks প্রভা
Related Posts
Trump Platinum Card

Trump’s $5 Million ‘Platinum Card’ Offers Fast-Track US Residency, Bypassing H-1B Visa Hurdles

December 13, 2025
AI bubble

Dow Jones Record High Hits as AI Bubble Fears Spark Tech Exodus

December 13, 2025
Scott Rudin’s Broadway Return Cut Short as Play Announces Early Closure

Scott Rudin’s Broadway Return Cut Short as Play Announces Early Closure

December 13, 2025
Latest News
Trump Platinum Card

Trump’s $5 Million ‘Platinum Card’ Offers Fast-Track US Residency, Bypassing H-1B Visa Hurdles

AI bubble

Dow Jones Record High Hits as AI Bubble Fears Spark Tech Exodus

Scott Rudin’s Broadway Return Cut Short as Play Announces Early Closure

Scott Rudin’s Broadway Return Cut Short as Play Announces Early Closure

Ben Affleck holiday drama

Ben Affleck Faces Holiday Showdown: Ex-Wives Garner and Lopez Demand Separate Celebrations

Wealthfront IPO

Wealthfront IPO Opens Strongly: A New Era for Robo-Advisors Begins

Fordham MBA ranking

Fordham MBA Ranking Soars to #40 in Latest National Business School Report

Philadelphia Eagles slump

Philadelphia Eagles Slump Deepens as Jordan Davis Vows Unwavering Support

Fischmas update

Fischmas Update Arrives: New Winter Village and Limited-Time Fish Await Players

Rehab Addict

Rehab Addict Finally Gets Return Date: New Episodes Land on HGTV in 2026

White House ballroom

Trump’s White House Ballroom Project Sparks Federal Lawsuit Over Approval Process

  • Home
  • Bangladesh
  • Business
  • International
  • Entertainment
  • Sports
  • বাংলা
© 2025 ZoomBangla News - Powered by ZoomBangla

Type above and press Enter to search. Press Esc to cancel.