Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

FBI is buying location data to track US citizens, director confirms

This startup wants to make enterprise software more like a prompt

Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Sam Altman’s thank you to coders draws memes

    19 March 2026

    The Pentagon is developing alternatives to Anthropic, the report said

    18 March 2026

    Mistral bets on ‘build your own AI’, as with OpenAI, Anthropic in business

    18 March 2026

    Picsart Now Lets Creators ‘Hire’ AI Assistants Through Agent Market

    17 March 2026

    Nvidia’s version of OpenClaw could solve its biggest problem: security

    17 March 2026
  • Apps

    Rebel Audio is a new AI podcasting tool aimed at first-time creators

    19 March 2026

    Google’s Personal Intelligence feature is expanding to all US users

    18 March 2026

    Kagi brings its “small web” of an all-human web to mobile devices

    18 March 2026

    Gamma adds AI image creation tools in a bid to take on Canva and Adobe

    17 March 2026

    Apple acquires video editing software company MotionVFX

    17 March 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

    17 March 2026

    Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

    16 March 2026

    India neobank Fi removes banking services on its platform

    11 March 2026

    X taps William Shatner to give invitations to his payment service, X Money

    4 March 2026

    Stripe wants to turn your AI costs into a profit center

    3 March 2026
  • Hardware

    CEO Carl Pei says nothing about smartphone apps disappearing as they’re replaced by artificial intelligence agents

    18 March 2026

    MacBook Neo, AirPods Max 2, iPhone 17e and everything else Apple announced this month

    18 March 2026

    Oura enters India’s smart ring market with Ring 4

    17 March 2026

    Apple quietly launches AirPods Max 2

    17 March 2026

    The MacBook Neo is “the most repairable MacBook” in years, according to iFixit

    16 March 2026
  • Media & Entertainment

    Patreon CEO calls AI companies’ fair use argument ‘bogus’, says creators should be paid

    18 March 2026

    Meet Vurt, the first mobile streaming platform for indie filmmakers embracing vertical video

    18 March 2026

    BuzzFeed debuts AI applications for new revenue

    17 March 2026

    Facebook makes it easy for creators to report copycats

    14 March 2026

    Spotify will let you edit your taste profile to control your recommendations

    13 March 2026
  • Security

    FBI is buying location data to track US citizens, director confirms

    19 March 2026

    Russians caught stealing personal data from Ukrainians with new advanced iPhone hacking tools

    18 March 2026

    Stryker says it is restoring systems after pro-Iranian hackers wiped out thousands of employee devices

    17 March 2026

    Wiz Investor Unpacks Google’s $32 Billion Acquisition

    15 March 2026

    Law enforcement shuts down botnet consisting of tens of thousands of hacked routers

    12 March 2026
  • Startups

    This startup wants to make enterprise software more like a prompt

    19 March 2026

    H&M wants to make clothes out of CO2 using this startup’s technology

    18 March 2026

    Why Garry Tan’s Claude Code setup has gotten so much love and hate

    18 March 2026

    Walmart-backed PhonePe shelvs IPO as global tensions roil markets

    16 March 2026

    Unacademy to be acquired by upGrad in share swap deal as India’s edtech sector consolidates

    16 March 2026
  • Transportation

    EV startup Harbinger unveils smaller work truck with electric and hybrid variants

    18 March 2026

    Rivian spin-out Mind Robotics raises $500M for AI-powered industrial robots

    17 March 2026

    Drivers in fatal Ford BlueCruise crashes were likely distracted before the crash

    17 March 2026

    Introducing the Rivian R2: See what $57,990 gets you

    15 March 2026

    Honda is killing its EVs — and any chance of competing in the future

    15 March 2026
  • Venture

    Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

    19 March 2026

    AI ‘boys club’ could widen wealth gap for women, says Rana el Kaliouby

    18 March 2026

    Billionaires made a promise – now some want to leave

    17 March 2026

    Antonio Gracias Says He Longs For ‘Pre-Entropic’ Startups – Those Built To Survive Chaos

    17 March 2026

    Founded by a father-son duo, Nyne gives AI agents the human context they’ve been missing

    14 March 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Home Depot exposed access to internal systems for a year, researcher says
Security

Home Depot exposed access to internal systems for a year, researcher says

techtost.comBy techtost.com13 December 202502 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Home Depot Exposed Access To Internal Systems For A Year,
Share
Facebook Twitter LinkedIn Pinterest Email

A security researcher said Home Depot exposed access to its internal systems for a year after one of its employees posted a private access token online, likely by mistake. The researcher found the exposed token and attempted to privately notify Home Depot of its security flaw, but was ignored for several weeks.

The report has now been corrected after TechCrunch contacted company representatives last week.

Security researcher Ben Zimmerman told TechCrunch that, in early November, it found a published GitHub access token belonging to a Home Depot employee that was exposed sometime in early 2024.

When testing the token, Zimmermann said it granted access to hundreds of private Home Depot source code repositories hosted on GitHub and allowed the ability to modify their content.

The researcher said the keys allowed access to Home Depot’s cloud infrastructure, including order fulfillment and inventory management systems, and code development pipelines, among other systems. Home Depot has hosted much of its developer and engineering infrastructure on GitHub since 2015, according to a customer profile on the GitHub website.

Zimmermann said he sent several emails to Home Depot but did not receive a response.

Nor did he get a response from Home Depot’s chief information security officer, Chris Lanzilotta, after sending a message through LinkedIn.

Zimmermann told TechCrunch that he has uncovered several similar openings in recent months at companies, which have thanked him for his findings.

“Home Depot is the only company that ignored me,” he said.

Since Home Depot has no way to report security flaws, such as a vulnerability disclosure or bug bounty program, Zimmermann reached out to TechCrunch in an attempt to correct the report.

When reached by TechCrunch on Dec. 5, Home Depot spokesman George Lane acknowledged receipt of our email but did not respond to subsequent emails seeking comment. The exposed token is no longer online and the researcher said access to the token was revoked shortly after we contacted them.

We also asked Lane if Home Depot has the technical means, such as logs, to determine if anyone else used the token during the months it was online to access any of Home Depot’s internal systems. We didn’t hear back.

access cyber security data breach Depot Exclusive exposed GitHub home home depot Internal researcher systems year
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRetro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll
Next Article Google Translate now lets you listen to real-time translations on your headphones
bhanuprakash.cg
techtost.com
  • Website

Related Posts

FBI is buying location data to track US citizens, director confirms

19 March 2026

Russians caught stealing personal data from Ukrainians with new advanced iPhone hacking tools

18 March 2026

H&M wants to make clothes out of CO2 using this startup’s technology

18 March 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

FBI is buying location data to track US citizens, director confirms

19 March 2026

This startup wants to make enterprise software more like a prompt

19 March 2026

Sequen raised $16 million to bring TikTok-style personalization technology to any consumer company

19 March 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Kalshi’s legal woes pile up as Arizona files first criminal charges for ‘illegal gambling operation’

17 March 2026

Fuse raises $25M to disrupt legacy loan origination systems used by US credit unions

16 March 2026

India neobank Fi removes banking services on its platform

11 March 2026
Startups

This startup wants to make enterprise software more like a prompt

H&M wants to make clothes out of CO2 using this startup’s technology

Why Garry Tan’s Claude Code setup has gotten so much love and hate

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.