chiprook
← Security
SecurityOctober 1, 2026, 01:08

Over 543,000 valid credentials found exposed in public GitHub repos

Truffle Security scanned 224 million repositories and 58 billion files and found 543,699 unique credentials that were still valid in July. The median time a credential stayed publicly accessible was 784 days, with the oldest dating back to 2009. About 36.8% of the leaks appeared after GitHub enabled Push Protection by default.

Over 543,000 valid credentials found exposed in public GitHub repos
#GitHub#TruffleSecurity#GoogleCloud
Read next
Security

Hardcoded MCP Credentials Found in Public GitHub Files

Security

GitHub lost 3,800 repos after malicious VSCode extension

Security

CrowdSec: TanStack npm Attack Led to Copy of 170 Private GitHub Repos

Security

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer