Open source bug leaves hundreds of thousands of sites open to attack

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Hundreds of thousands of websites, including thousands using the .gov domain, are at risk of data loss, experts have warned.

Cybersecurity researchers from Defense.com have discovered a vulnerability in the open source development tool Git which, if not addressed, allows threat actors the keys to the kingdom.

Apparently, there is a number of .git folders that need to be hidden, but in many cases, are not. While a serious flaw, it’s not directly Git’s fault, the researchers are saying, but rather Git users failing to follow best practice. With the help of a specially crafted Google dork, a threat actor would be able to find these folders, and download their contents. 

Eliminating risk

The files contained within these folders usually hold entire codebase history, previous code changes, comments, security keys, as well as sensitive remote paths containing secrets and files with plain-text passwords. Besides the obvious threat of exposing passwords and sensitive data, there’s also a hidden threat - hackers could review the code and find additional flaws which they probably won’t be fixing but instead - abusing. What’s more, these folders could contain database credentials and API keys, further giving threat actors access to sensitive user data. 

In total, Defense.com says, 332,000 websites were found as potentially vulnerable, including 2,500 residing on the .gov domain. 

Open source technology always has the potential for security flaws, being rooted in publicly accessible code. However, this level of vulnerability is not acceptable,” commented Oliver Pinson-Roxburgh, CEO of Defense.com. “Organizations, including the UK government, must ensure they monitor their systems and take immediate steps to remediate risk.”

Git is a hugely popular open-source version control system, counting more than 80 million active users, Pinson-Roxburgh adds, saying this type of vulnerability, on such a popular platform, can have “serious consequences” for affected firms. 

“Whilst it is true that some folders would have been purposefully left accessible, the vast majority will be unaware of the threat they are facing,” he concluded. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Shadowed hands on a digital background reaching for a login prompt.
This worrying Git flaw could lead to users leaking credentials
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
Shadowed hands on a digital background reaching for a login prompt.
A flaw in Google OAuth system is exposing millions of users via abandoned accounts
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge benchmark leak has eased my worries about its performance
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
Google Pixel 9 in green Wintergreen color showing AI features on screen
Older Pixels just got a big performance boost, while the Pixel 9a is lacking a key feature
Wonka poster
Netflix cooks up sweet new reality TV series based on Charlie and the Chocolate Factory, and it's a dream come true for me
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can