chiprook
← Security
SecurityOctober 1, 2026, 16:43

Truffle Security finds 543,699 active credentials exposed on GitHub

Truffle Security scanned 224 million public GitHub repositories and found 1,103,438 exposed credentials, of which 543,699 were still active as of July 2026. The oldest is an AWS key committed in 2009, and the median exposure window is 784 days. Nearly half of the leaks appeared after GitHub enabled free alerts and default push protection.

Truffle Security finds 543,699 active credentials exposed on GitHub
#GitHub#TruffleSecurity#Google#MongoDB
Read next
Security

Over 543,000 valid credentials found exposed in public GitHub repos

Security

ZoomEye finds 1.89 million exposed MongoDB services

Security

GitGuardian Deploys AI Agents to Triage Leaked Credentials

Security

Agent skill harvesting browser credentials had 60,000 GitHub stars