Over 543,000 valid credentials found exposed in public GitHub repos
Truffle Security scanned 224 million repositories and 58 billion files and found 543,699 unique credentials that were still valid in July. The median time a credential stayed publicly accessible was 784 days, with the oldest dating back to 2009. About 36.8% of the leaks appeared after GitHub enabled Push Protection by default.
- 543,699 unique live credentials found across 1.1 million files and repositories
- Median exposure time was 784 days; oldest credential dated from 2009
- 36.8% of leaks appeared after Push Protection went default in February 2024
- Of 126,963 exposed Google Cloud keys, 69,041 were still working
Read next
Security