A security researcher discovered a GitHub admin token in the login page of a Hanwha security camera, which had admin privileges to hundreds of repositories. The token was found in the camera's firmware, which was extracted and analyzed. The researcher notified Hanwha, and the token was revoked within 12 hours. The camera's firmware also contained IP addresses assigned to the US Department of Defense, raising questions about the company's relationship with the DoD.