Skip to main content
Security

My security camera shipped a GitHub admin token in its login page

A security researcher discovered a GitHub administrative token embedded in the login page of Hanwha Vision security cameras and reported the exposure to the company, which revoked the credential within 12 hours, the researcher said. The researcher reverse-engineered firmware for Hanwha Vision cameras, decrypting the root filesystem using a hardcoded AES key and initialization vector found in the fwupgrader binary. A scan of the extracted filesystem with TruffleHog revealed a GitHub token duplicated in approximately 30 files that granted administrative privileges to hundreds of repositories in the organization's GitHub account. The token appeared to have been included because the camera's user interface, built with Vite, was configured to write the entirety of the CI job's environment variables into the build artifacts at compile time. The researcher downloaded and analyzed roughly 500 firmware images across the product line and found the same token in only three images. The researcher reported the finding to Hanwha Vision's security contact and received confirmation that the token had been revoked. The exposed environment variables also contained IP addresses assigned to the U.S. Department of Defense, though the significance of that data was not determined.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from hhh.hn and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...

Security AI
Security AI

Microsoft reports ASCII-smuggling use in email spam

Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...

Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...