Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

TikTok now allows Apple Music subscribers to play entire songs without leaving the app

The pro-Iranian hacktivist group says it is behind the attack on medical technology giant Stryker

Ride-hailing inDrive acquires Pakistan’s Krave Mart to boost grocery delivery

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    AI ‘Actress’ Tilly Norwood Releases Worst Song I’ve Ever Heard

    12 March 2026

    AI apps struggle with long-term retention, according to a new report

    11 March 2026

    Amazon is launching its AI health assistant on its website and app

    11 March 2026

    Sandbar secures $23M Series A for AI note-taking ring

    10 March 2026

    OpenAI and Google employees are quick to defend Anthropic in the DOD lawsuit

    10 March 2026
  • Apps

    Google Play adds new paid and PC games, game tests, community posts and more

    12 March 2026

    Google brings Gemini to Chrome in India

    11 March 2026

    YouTube surpasses Disney, Paramount, WBD in ad revenue in 2025

    11 March 2026

    X says it will suspend creators from revenue sharing program for AI posts without ‘armed conflict’ tag

    10 March 2026

    Periwinkle makes it even easier to host social media on Bluesky’s AT Protocol

    10 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    India neobank Fi removes banking services on its platform

    11 March 2026

    X taps William Shatner to give invitations to his payment service, X Money

    4 March 2026

    Stripe wants to turn your AI costs into a profit center

    3 March 2026

    3 days left: Save up to $680 on your ticket to Disrupt 2026

    25 February 2026

    More startups surpass $10M ARR in 3 months than ever before

    24 February 2026
  • Hardware

    Canopii seems to succeed where the old indoor farms failed

    11 March 2026

    Hyperscale Power is the latest startup to challenge 140-year-old transformer technology

    10 March 2026

    Whoop is launching a new blood test focused on women’s health

    10 March 2026

    Honor says its ‘Robot phone’ with moving camera can dance to music

    8 March 2026

    Apple unveils M5 Pro and M5 Max chips with new ‘Fusion Architecture’

    8 March 2026
  • Media & Entertainment

    TikTok now allows Apple Music subscribers to play entire songs without leaving the app

    12 March 2026

    WordPress debuts a private workspace that runs in your browser via a new service, my.WordPress.net

    11 March 2026

    “Pokémon Pokopia” is a game about restoring a broken world — and I love it

    11 March 2026

    YouTube extends fake AI detection to politicians, government officials and journalists

    10 March 2026

    Xprize Founder Peter Diamandis Launches New Contest To Announce New ‘Star Trek’

    10 March 2026
  • Security

    The pro-Iranian hacktivist group says it is behind the attack on medical technology giant Stryker

    12 March 2026

    Salt Typhoon hacks the world’s phone and internet giants — here’s where they’ve been hit

    11 March 2026

    DOGE employee stole Social Security data and thumbed it, report says

    11 March 2026

    US military contractor likely built iPhone hacking tools used by Russian spies in Ukraine

    10 March 2026

    An iPhone hacking toolkit used by Russian spies likely came from a US military contractor

    10 March 2026
  • Startups

    Ride-hailing inDrive acquires Pakistan’s Krave Mart to boost grocery delivery

    12 March 2026

    Google completes $32 billion acquisition of cloud cybersecurity startup Wiz

    11 March 2026

    Mandiant founder just raised $190 million for autonomous AI security agent startup

    11 March 2026

    AI networking startup Eridu emerges from stealth with hefty $200M Series A

    10 March 2026

    Bluesky CEO Jay Graber is stepping down

    10 March 2026
  • Transportation

    Nuro is testing its autonomous vehicle technology on the streets of Tokyo

    12 March 2026

    Zoox plans to put its robotaxis on the Uber app in Vegas this year

    11 March 2026

    GM figured out how to deal with EV uncertainty with the Chevy Bolt

    11 March 2026

    Electric air taxi maker Archer hits back at Joby alleging hidden Chinese ties

    10 March 2026

    Electric air taxis are set to fly in 26 states

    10 March 2026
  • Venture

    This SpaceX Veteran Says The Next Big Thing In Space Is Satellites Returning To Earth

    10 March 2026

    Founders Fund is approaching $6 billion for its latest growth fund, sources say

    10 March 2026

    Robinhood’s startup fund stumbles in its NYSE debut

    7 March 2026

    City Detect, which uses artificial intelligence to help cities stay safe and clean, raises $13M Series A

    7 March 2026

    Lio raises $30 million from Andreessen Horowitz and others to automate business procurement

    5 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Home Depot exposed access to internal systems for a year, researcher says
Security

Home Depot exposed access to internal systems for a year, researcher says

techtost.comBy techtost.com13 December 202502 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Home Depot Exposed Access To Internal Systems For A Year,
Share
Facebook Twitter LinkedIn Pinterest Email

A security researcher said Home Depot exposed access to its internal systems for a year after one of its employees posted a private access token online, likely by mistake. The researcher found the exposed token and attempted to privately notify Home Depot of its security flaw, but was ignored for several weeks.

The report has now been corrected after TechCrunch contacted company representatives last week.

Security researcher Ben Zimmerman told TechCrunch that, in early November, it found a published GitHub access token belonging to a Home Depot employee that was exposed sometime in early 2024.

When testing the token, Zimmermann said it granted access to hundreds of private Home Depot source code repositories hosted on GitHub and allowed the ability to modify their content.

The researcher said the keys allowed access to Home Depot’s cloud infrastructure, including order fulfillment and inventory management systems, and code development pipelines, among other systems. Home Depot has hosted much of its developer and engineering infrastructure on GitHub since 2015, according to a customer profile on the GitHub website.

Zimmermann said he sent several emails to Home Depot but did not receive a response.

Nor did he get a response from Home Depot’s chief information security officer, Chris Lanzilotta, after sending a message through LinkedIn.

Zimmermann told TechCrunch that he has uncovered several similar openings in recent months at companies, which have thanked him for his findings.

“Home Depot is the only company that ignored me,” he said.

Since Home Depot has no way to report security flaws, such as a vulnerability disclosure or bug bounty program, Zimmermann reached out to TechCrunch in an attempt to correct the report.

When reached by TechCrunch on Dec. 5, Home Depot spokesman George Lane acknowledged receipt of our email but did not respond to subsequent emails seeking comment. The exposed token is no longer online and the researcher said access to the token was revoked shortly after we contacted them.

We also asked Lane if Home Depot has the technical means, such as logs, to determine if anyone else used the token during the months it was online to access any of Home Depot’s internal systems. We didn’t hear back.

access cyber security data breach Depot Exclusive exposed GitHub home home depot Internal researcher systems year
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRetro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll
Next Article Google Translate now lets you listen to real-time translations on your headphones
bhanuprakash.cg
techtost.com
  • Website

Related Posts

The pro-Iranian hacktivist group says it is behind the attack on medical technology giant Stryker

12 March 2026

Ride-hailing inDrive acquires Pakistan’s Krave Mart to boost grocery delivery

12 March 2026

India neobank Fi removes banking services on its platform

11 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

TikTok now allows Apple Music subscribers to play entire songs without leaving the app

12 March 2026

The pro-Iranian hacktivist group says it is behind the attack on medical technology giant Stryker

12 March 2026

Ride-hailing inDrive acquires Pakistan’s Krave Mart to boost grocery delivery

12 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

India neobank Fi removes banking services on its platform

11 March 2026

X taps William Shatner to give invitations to his payment service, X Money

4 March 2026

Stripe wants to turn your AI costs into a profit center

3 March 2026
Startups

Ride-hailing inDrive acquires Pakistan’s Krave Mart to boost grocery delivery

Google completes $32 billion acquisition of cloud cybersecurity startup Wiz

Mandiant founder just raised $190 million for autonomous AI security agent startup

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.