Reddit
A Hanwha Security Camera Shipped a Live GitHub Admin Token in Its Login Page HTML
A researcher found a GitHub admin token embedded in the login page of a Hanwha Wisenet XNP-9300RW camera, then extracted and analyzed roughly 500 Hanwha firmware images — 62% were extractable, and three contained the same token. Hanwha responded through its open security-reporting address and revoked the token within 12 hours, a response time worth noting against the industry norm. The thread reached 120 points on Hacker News July 24 and lands the same week as the Hugging Face breach as a reminder that credential hygiene in build artifacts is where agent-era attacks actually start.
↳ Follow the thread