Security camera exposed GitHub admin token on its login page
A recent report highlighted a security camera that leaked sensitive credentials. The device’s login page included a GitHub admin token in the page source. The token granted
A recent report highlighted a security camera that leaked sensitive credentials. The
device’s login page included a GitHub admin token in the page source. The token granted
full administrative access to the associated GitHub account. Researchers discovered the
exposure during routine testing of the camera’s web interface. The vendor was notified and
began investigating the cause of the leak. The incident underscores the risks of embedded
credentials in IoT devices. Experts recommend auditing firmware and removing hard‑coded
tokens before release. Users are advised to rotate any exposed credentials and monitor for
unauthorized activity.