Over 543,000 valid credentials left exposed on GitHub
More than 543,000 active credentials were publicly accessible on GitHub as of July, according to research by Truffle Security. Scanning over 224 million repositories found credentials were typically left exposed for over two years, with some dating back more than a decade. Nearly 37% of valid credentials became public after GitHub enabled its Push Protection safeguard for everyone in February 2024.
- Researchers scanned 224 million repositories for leaks
- Median exposure time was 784 days per credential
- About 200,000 remained exposed after Push Protection began
- Some credential types, like Google Cloud keys, rarely get revoked
- Credential leaks have more than doubled since 2015
Sources covering this
In this story
More in Cybersecurity
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…
OpenAI disrupts novel AI distillation attack it links to China
OpenAI announced it has stopped a coordinated attempt to extract and distill reasoning capabilities from its AI systems, attributing a…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
Unpatched Zimbra flaw exploited to steal emails and credentials
A critical security vulnerability in Zimbra Collaboration Suite has been exploited by attackers to access emails and authentication data…