Techzine.Eu Strix Discovers Critical GitHub Token Exposure at Baseten
Article Content
- •Strix found a live GitHub token with admin rights in Baseten's infrastructure.
- •The token had been active for over three years, granting access to sensitive repositories.
- •Baseten's security team responded quickly, rotating the token within a day.
Security startup Strix identified a critical vulnerability in Baseten's infrastructure, discovering a live GitHub personal access token with repository-level admin rights within 25 minutes. The token, associated with the 'basetenbot' account, had been active since March 2023 and provided access to several private repositories, including customer-specific ones. Strix performed this scan as part of their due diligence before using Baseten's services. Upon discovery, Baseten's security team promptly confirmed the issue, locked down the affected project, and rotated the token within a day. This incident highlights the potential vulnerabilities in cloud infrastructure providers, particularly in the AI neocloud sector. Strix's autonomous hacking agent, Strix, utilized reconnaissance techniques to uncover the token through a public Harbor container registry associated with Baseten. The incident raises concerns about the security practices of neocloud providers, emphasizing the need for thorough vendor assessments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Baseten in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…