tokens

  • Blog

    Hackers ramp up scans for leaked Git tokens and secrets

    Threat actors are intensifying internet-wide scanning for Git configuration files that can reveal sensitive secrets and authentication tokens used to compromise cloud services and source code repositories. In a new report from threat monitoring firm GreyNoise, researchers have recorded a massive spike in searches for exposed Git configs between April 20-21, 2025. “GreyNoise observed nearly 4,800 unique IP addresses daily…

    Read More »
  • Blog

    Clair Obscur Expedition 33: All Festival Tokens Locations and How to Get Them

    Clair Obscur Expedition 33 is filled with secrets and a ton of side objectives, which start showcasing from the very beginning of the game. During the game’s prologue, Gustave eventually finds himself in the Festival after the Gommage. Here at the festival, Gustave can spend Festival Tokens to get exclusive items from the vendors. However, he doesn’t start with all…

    Read More »
  • Blog

    Malicious PyPi package steals Discord auth tokens from devs

    A malicious package named ‘pycord-self’ on the Python package index (PyPI) targets Discord developers to steal authentication tokens and plant a backdoor for remote control over the system. The package mimics the highly popular ‘discord.py-self,’ which has nearly 28 million downloads, and even offers the functionality of the legitimate project. The official package is a Python library that allows communication with Discord’s…

    Read More »
  • Blog

    Malicious Rspack, Vant packages published using stolen NPM tokens

    Three popular npm packages, @rspack/core, @rspack/cli, and Vant, were compromised through stolen npm account tokens, allowing threat actors to publish malicious versions that installed cryptominers. The supply chain attack, spotted by both Sonatype and Socket researchers, deployed the XMRig cryptocurrency miner on compromised systems for mining the hard-to-trace Monero privacy cryptocurrency. Additionally, Sonatype discovered that all three npm packages fell…

    Read More »
  • Blog

    Internet Archive breached again through stolen access tokens

    The Internet Archive was breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens. Since last night, BleepingComputer has received numerous messages from people who received replies to their old Internet Archive removal requests, warning that the organization has been breached as they did not correctly rotate their stolen…

    Read More »
  • Blog

    GitHub Actions artifacts found leaking auth tokens in popular projects

    Multiple high-profile open-source projects, including those from Google, Microsoft, AWS, and Red Hat, were found to leak GitHub authentication tokens through GitHub Actions artifacts in CI/CD workflows. Attackers stealing these tokens could gain unauthorized access to private repositories, steal source code, or inject malicious code into projects. The discovery by Palo Alto Networks’ Unit 42 prompted action by owners of…

    Read More »
Back to top button
close