By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Home
  • Gulf News
  • World
  • Business
  • Technology
  • Sports
  • Lifestyle
Search
Countries
More Topics
  • Health
  • Entertainment
Site Links
  • Customize Interests
  • Bookmarks
  • Newsletter
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Reading: Home Depot exposed access to internal systems for a year, says researcher
Share
Notification Show More
Latest News
Oman Air announces new scheduled flights to Copenhagen, Baghdad, Taif, and Moscow
Gulf
1,396 people arrested for operating illegal passenger transport services last week
Gulf
Awqaf Studies Center releases sixth issue of Al-Waqf journal
Gulf
UNICEF Oman organises dialogue sessions for students in North Al Sharqiyah
Gulf
Bondi Beach shooting: What we know so far
World
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • World
  • Business
  • Entertainment
  • Lifestyle
  • Sports
Search
  • Home
  • Gulf
  • Business
  • More News
    • World
    • Technology
    • Lifestyle
    • Entertainment
    • Sports
Have an existing account? Sign In
Follow US
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Gulf Press > Technology > Home Depot exposed access to internal systems for a year, says researcher
Technology

Home Depot exposed access to internal systems for a year, says researcher

News Room
Last updated: 2025/12/15 at 12:57 AM
News Room
Share
6 Min Read
SHARE

Home Depot recently resolved a significant security breach after a publicly exposed GitHub access token granted unauthorized access to internal systems for nearly a year. The token, belonging to a Home Depot employee, was discovered in early November and allowed access to sensitive source code, cloud infrastructure, and potentially customer data. The issue was addressed after TechCrunch alerted the company, highlighting a lack of responsiveness to initial security reports.

Contents
Initial Attempts at DisclosureImpact and Remediation

Home Depot Security Incident: A Year of Exposure

The incident centered around a GitHub access token inadvertently published online by a Home Depot employee sometime in early 2024. Security researcher Ben Zimmermann identified the token and quickly determined its extensive permissions. He found it provided access to hundreds of private repositories containing Home Depot’s source code, as well as systems related to order fulfillment and inventory management.

GitHub has become a central hub for software development, and many companies, including Home Depot since 2015, utilize the platform to host and manage their code. Access tokens are designed to allow automated tools and developers to interact with these repositories, but when exposed publicly, they can become a major vulnerability. This particular token’s broad permissions raised serious concerns about potential data compromise.

Initial Attempts at Disclosure

Zimmermann attempted to privately notify Home Depot of the exposed token through multiple email addresses. However, his outreach went unanswered for several weeks. He even reached out to Home Depot’s Chief Information Security Officer, Chris Lanzilotta, via LinkedIn, but again received no response.

This lack of communication is particularly noteworthy given the increasing frequency of similar exposures and the generally positive reception researchers receive when reporting them. Zimmermann stated that Home Depot was the only company to ignore his findings in recent months, despite successfully alerting others to similar vulnerabilities.

Without a formal vulnerability disclosure program or bug bounty program in place, Zimmermann ultimately contacted TechCrunch to facilitate a resolution. This highlights a growing need for companies to establish clear channels for security researchers to report potential issues responsibly.

Impact and Remediation

The exposed token potentially allowed unauthorized users to view, modify, and even delete sensitive source code. Access to cloud infrastructure and systems managing order fulfillment and inventory could have led to disruptions in service or, more seriously, data breaches. The extent of any actual exploitation remains unclear.

Following inquiries from TechCrunch on December 5th, Home Depot acknowledged receipt of the initial email but did not immediately provide further comment. The exposed token was subsequently removed from public view, and Zimmermann confirmed that its access privileges were revoked.

However, questions remain regarding whether the token was used maliciously during the period it was exposed. TechCrunch specifically asked Home Depot if logs exist to determine if unauthorized access occurred, but did not receive a response. Analyzing these logs would be crucial to understanding the full scope of the incident and identifying any compromised data.

Broader Implications for Software Supply Chain Security

This incident underscores the growing importance of software supply chain security. Companies increasingly rely on third-party platforms like GitHub to manage their code, making them potential targets for attackers. A compromised access token can act as a gateway to an organization’s entire development infrastructure.

Additionally, the lack of a vulnerability disclosure program at Home Depot hindered the timely resolution of the issue. Such programs encourage responsible disclosure by providing a clear and safe channel for researchers to report vulnerabilities without fear of legal repercussions. They also allow companies to proactively address security flaws before they can be exploited.

The incident also raises concerns about the security practices of individual employees. While the token was likely exposed accidentally, it highlights the need for robust training and policies regarding the handling of sensitive credentials. Regular audits and automated scanning for exposed secrets can also help prevent similar incidents in the future. The concept of credential management is vital in preventing these types of breaches.

The increasing reliance on cloud services and DevOps practices necessitates a shift in security thinking. Traditional perimeter-based security is no longer sufficient, and organizations must adopt a more holistic approach that encompasses the entire software development lifecycle. This includes implementing strong authentication measures, regularly reviewing access permissions, and proactively monitoring for suspicious activity.

Looking ahead, it remains to be seen whether Home Depot will conduct a thorough investigation to determine the extent of any potential damage caused by the exposed token. The company has not publicly committed to such an investigation, nor has it announced plans to implement a vulnerability disclosure program. Stakeholders will be watching for any further announcements regarding this data security incident and the steps Home Depot takes to prevent similar occurrences in the future.

The company’s response, or lack thereof, will likely influence perceptions of its commitment to protecting customer and company data.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
I have read and agree to the terms & conditions
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
News Room December 15, 2025
Share this Article
Facebook Twitter Copy Link Print
Previous Article Saudi Arabia to roll out new foreign property ownership law in 2026
Next Article Rain hits parts of the UAE, residents urged to prepare for unstable weather
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Oman Air announces new scheduled flights to Copenhagen, Baghdad, Taif, and Moscow
Gulf December 15, 2025
1,396 people arrested for operating illegal passenger transport services last week
Gulf December 15, 2025
Awqaf Studies Center releases sixth issue of Al-Waqf journal
Gulf December 15, 2025
UNICEF Oman organises dialogue sessions for students in North Al Sharqiyah
Gulf December 15, 2025

You Might also Like

Technology

Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll

December 14, 2025
Technology

Google Translate now lets you hear real-time translations in your headphones

December 14, 2025
Technology

Trump’s AI executive order promises ‘one rulebook’ — startups may get legal limbo instead

December 14, 2025
Technology

Data breach at credit check giant 700Credit affects at least 5.6 million

December 14, 2025
Technology

Netflix growing up, data center jet engines, and the circular AI economy

December 14, 2025
Technology

Microsoft buys 3.6M metric tons of carbon removal from bioenergy plant

December 14, 2025
Technology

OK, what’s going on with LinkedIn’s algo?

December 14, 2025
Technology

Google and Apple roll out emergency security updates after zero-day attacks

December 13, 2025
//

Gulf Press is your one-stop website for the latest news and updates about Arabian Gulf and the world, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of ue
  • Advertise
  • Contact

How Topics

  • Gulf News
  • International
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

I have read and agree to the terms & conditions
Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?