Truffle Security found more than 1.1 million exposed credentials in public GitHub repositories, with 543,699 still active when retested in July 2026. The leaks include long-lived AWS keys, Google Cloud service accounts, MongoDB connection strings, and Google API keys, showing that many secrets were exposed but never revoked. #GitHub #TruffleSecurity #AWS #GoogleCloud #MongoDB
Keypoints
- Truffle Security scanned 224 million public GitHub repositories.
- It found 1,103,438 exposed credentials in August 2025.
- 543,699 credentials were still active when tested in July 2026.
- The oldest exposed secret was an AWS key committed in 2009.
- Google Cloud service accounts, MongoDB strings, and Google API keys were the most common leaks.
Read More: https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/