Security camera exposed GitHub admin token on its login page

A recent report highlighted a security camera that leaked sensitive credentials. The device’s login page included a GitHub admin token in the page source. The token granted

A recent report highlighted a security camera that leaked sensitive credentials. The device’s login page included a GitHub admin token in the page source. The token granted full administrative access to the associated GitHub account. Researchers discovered the exposure during routine testing of the camera’s web interface. The vendor was notified and began investigating the cause of the leak. The incident underscores the risks of embedded credentials in IoT devices. Experts recommend auditing firmware and removing hard‑coded tokens before release. Users are advised to rotate any exposed credentials and monitor for unauthorized activity.