By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Home
  • Gulf News
  • World
  • Business
  • Technology
  • Sports
  • Lifestyle
Search
Countries
More Topics
  • Health
  • Entertainment
Site Links
  • Customize Interests
  • Bookmarks
  • Newsletter
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Reading: Home Depot exposed access to internal systems for a year, says researcher
Share
Notification Show More
Latest News
Sixth edition of Katara International Amber Exhibition concludes
Gulf
Saudi Arabia, Morocco sign renewable energy cooperation program
Gulf
Department of Meteorology warns of strong wind, high sea tonight
Gulf
Qatar Education Minister holds talks with Saudi and Yemeni counterparts in Riyadh
Gulf
Parliament passes urgent government-drafted bill tightening rules for external auditors
Gulf
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • World
  • Business
  • Entertainment
  • Lifestyle
  • Sports
Search
  • Home
  • Gulf
  • Business
  • More News
    • World
    • Technology
    • Lifestyle
    • Entertainment
    • Sports
Have an existing account? Sign In
Follow US
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Gulf Press > Technology > Home Depot exposed access to internal systems for a year, says researcher
Technology

Home Depot exposed access to internal systems for a year, says researcher

News Room
Last updated: 2025/12/15 at 12:57 AM
News Room
Share
6 Min Read
SHARE

Home Depot recently resolved a significant security breach after a publicly exposed GitHub access token granted unauthorized access to internal systems for nearly a year. The token, belonging to a Home Depot employee, was discovered in early November and allowed access to sensitive source code, cloud infrastructure, and potentially customer data. The issue was addressed after TechCrunch alerted the company, highlighting a lack of responsiveness to initial security reports.

Contents
Initial Attempts at DisclosureImpact and Remediation

Home Depot Security Incident: A Year of Exposure

The incident centered around a GitHub access token inadvertently published online by a Home Depot employee sometime in early 2024. Security researcher Ben Zimmermann identified the token and quickly determined its extensive permissions. He found it provided access to hundreds of private repositories containing Home Depot’s source code, as well as systems related to order fulfillment and inventory management.

GitHub has become a central hub for software development, and many companies, including Home Depot since 2015, utilize the platform to host and manage their code. Access tokens are designed to allow automated tools and developers to interact with these repositories, but when exposed publicly, they can become a major vulnerability. This particular token’s broad permissions raised serious concerns about potential data compromise.

Initial Attempts at Disclosure

Zimmermann attempted to privately notify Home Depot of the exposed token through multiple email addresses. However, his outreach went unanswered for several weeks. He even reached out to Home Depot’s Chief Information Security Officer, Chris Lanzilotta, via LinkedIn, but again received no response.

This lack of communication is particularly noteworthy given the increasing frequency of similar exposures and the generally positive reception researchers receive when reporting them. Zimmermann stated that Home Depot was the only company to ignore his findings in recent months, despite successfully alerting others to similar vulnerabilities.

Without a formal vulnerability disclosure program or bug bounty program in place, Zimmermann ultimately contacted TechCrunch to facilitate a resolution. This highlights a growing need for companies to establish clear channels for security researchers to report potential issues responsibly.

Impact and Remediation

The exposed token potentially allowed unauthorized users to view, modify, and even delete sensitive source code. Access to cloud infrastructure and systems managing order fulfillment and inventory could have led to disruptions in service or, more seriously, data breaches. The extent of any actual exploitation remains unclear.

Following inquiries from TechCrunch on December 5th, Home Depot acknowledged receipt of the initial email but did not immediately provide further comment. The exposed token was subsequently removed from public view, and Zimmermann confirmed that its access privileges were revoked.

However, questions remain regarding whether the token was used maliciously during the period it was exposed. TechCrunch specifically asked Home Depot if logs exist to determine if unauthorized access occurred, but did not receive a response. Analyzing these logs would be crucial to understanding the full scope of the incident and identifying any compromised data.

Broader Implications for Software Supply Chain Security

This incident underscores the growing importance of software supply chain security. Companies increasingly rely on third-party platforms like GitHub to manage their code, making them potential targets for attackers. A compromised access token can act as a gateway to an organization’s entire development infrastructure.

Additionally, the lack of a vulnerability disclosure program at Home Depot hindered the timely resolution of the issue. Such programs encourage responsible disclosure by providing a clear and safe channel for researchers to report vulnerabilities without fear of legal repercussions. They also allow companies to proactively address security flaws before they can be exploited.

The incident also raises concerns about the security practices of individual employees. While the token was likely exposed accidentally, it highlights the need for robust training and policies regarding the handling of sensitive credentials. Regular audits and automated scanning for exposed secrets can also help prevent similar incidents in the future. The concept of credential management is vital in preventing these types of breaches.

The increasing reliance on cloud services and DevOps practices necessitates a shift in security thinking. Traditional perimeter-based security is no longer sufficient, and organizations must adopt a more holistic approach that encompasses the entire software development lifecycle. This includes implementing strong authentication measures, regularly reviewing access permissions, and proactively monitoring for suspicious activity.

Looking ahead, it remains to be seen whether Home Depot will conduct a thorough investigation to determine the extent of any potential damage caused by the exposed token. The company has not publicly committed to such an investigation, nor has it announced plans to implement a vulnerability disclosure program. Stakeholders will be watching for any further announcements regarding this data security incident and the steps Home Depot takes to prevent similar occurrences in the future.

The company’s response, or lack thereof, will likely influence perceptions of its commitment to protecting customer and company data.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
I have read and agree to the terms & conditions
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
News Room December 15, 2025
Share this Article
Facebook Twitter Copy Link Print
Previous Article Saudi Arabia to roll out new foreign property ownership law in 2026
Next Article Rain hits parts of the UAE, residents urged to prepare for unstable weather
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Sixth edition of Katara International Amber Exhibition concludes
Gulf January 16, 2026
Saudi Arabia, Morocco sign renewable energy cooperation program
Gulf January 16, 2026
Department of Meteorology warns of strong wind, high sea tonight
Gulf January 16, 2026
Qatar Education Minister holds talks with Saudi and Yemeni counterparts in Riyadh
Gulf January 16, 2026

You Might also Like

Technology

AI journalism startup Symbolic.ai signs deal with Rupert Murdoch’s News Corp

January 16, 2026
Technology

Silicon Valley’s messiest breakup is definitely headed to court

January 16, 2026
Technology

Anthropic taps former Microsoft India MD to lead Bengaluru expansion

January 16, 2026
Technology

Harmattan AI raises $200M Series B led by Dassault Aviation, becomes defense unicorn

January 16, 2026
Technology

Meta hires former Trump advisor Dina Powell McCormick as president and vice chair

January 15, 2026
Technology

Luminar lines up $22 million bidder for its lidar business

January 15, 2026
Technology

Netflix had a huge night at the 2026 Golden Globes with 7 wins

January 15, 2026
Technology

A New Jersey lawsuit shows how hard it is to fight deepfake porn

January 15, 2026
//

Gulf Press is your one-stop website for the latest news and updates about Arabian Gulf and the world, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of ue
  • Advertise
  • Contact

How Topics

  • Gulf News
  • International
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

I have read and agree to the terms & conditions
Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?