We got admin access to Baseten's production GitHub
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Security breach writeup revealing GitHub PAT token admin access to production, highly actionable for security and platform engineers.
Strix's autonomous hacking agent discovered a live GitHub personal access token with admin and push access to Baseten's production repositories, including their main product repo and GitOps infrastructure, by scanning a publicly accessible Harbor container registry. The token, dating from March 2023 and still active in July 2026, was found without any credentials by enumerating subdomains and pulling anonymous image layers. Baseten's security team rotated the token within a day of disclosure, but the incident demonstrates how exposed container registries can leak critical infrastructure credentials.
Alex Schapiro