Over 543,000 valid credentials exposed in public GitHub repositories

Over 543,000 valid credentials exposed in public GitHub repositories
Truffle Security found more than 543,000 valid credentials still exposed in public GitHub repositories in July, with some secrets remaining public for years despite GitHub’s safeguards. The study shows that Push Protection reduced some exposures, but many live secrets still fall outside its coverage, including database strings and Google API keys. #GitHub #TruffleSecurity #PushProtection

Keypoints

  • 543,699 unique valid credentials were found exposed across more than 1.1 million files and repositories.
  • The median time a credential stayed publicly accessible was 784 days.
  • About 10% of working credentials were older than 6.3 years, and the oldest dated back to 2009.
  • GitHub’s Push Protection blocked some leaks, but 36.8% of the live credentials were exposed after it was enabled by default.
  • More than half of the valid secrets were types not covered by default Push Protection, such as database connection strings and Google API keys.

Read More: https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/