Researchers Gained Admin Access to Baseten's Production GitHub in 25 Minutes via PAT Takeover
bearsyankees · hn · 2026-09-16
Security firm Strix published a writeup showing how they took over Baseten's production GitHub in just 25 minutes by abusing an over-scoped GitHub Personal Access Token (PAT).
The post walks through the full attack chain: how over-privileged PATs leak, how the token enabled lateral movement into production, and why long-lived credentials in CI/CD pipelines remain a systemic risk for AI infrastructure companies.
A useful cautionary case for any team wiring GitHub tokens into deployment pipelines.
More from Infra
- US data centers projected to use more natural gas than Germany and Japan combined by 2035 — Polymarket · 2026-09-16
- Princeton builds an erasable, light-programmed ultrathin semiconductor a few molecules thick — MengdiWang10 · 2026-09-16
- MacBook M5 Pro 48GB runs Qwen Flash at 13-14 tok/s — what's your local setup? — carloslfu · 2026-09-16
- Jensen Huang: Hyperscalers Plan Once a Year and Are 'Always Almost Wrong' on AI — rohanpaul_ai · 2026-09-16
- 2x5090 over 100G RPC runs Qwen at 90-100 tok/s decode, 3000 tok/s prefill — ilarp · 2026-09-16
- Chris Lattner to keynote PyTorch Conference on Mojo and MAX for heterogeneous compute — PyTorch · 2026-09-16