Over 543,000 Valid Credentials Exposed in Public GitHub Repositories
What Happened – Researchers at Truffle Security scanned 224 million public GitHub repositories and uncovered 543,699 unique, still‑working credentials. The median exposure time was 784 days, and 36.8 % of the live secrets appeared after GitHub’s Push Protection was enabled by default.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of code repositories is essential; a control‑assurance program should capture secret‑leak events in near‑real time and retain evidence for audit.
- Credential rotation and revocation policies must be enforceable and auditable, providing a defensible trail that demonstrates due diligence.
- Automated secret‑detection tools (e.g., Push Protection) reduce risk, but gaps remain—control owners need to map coverage to their risk register and supplement with supplemental scans.
Who Is Affected – Software developers, SaaS vendors, cloud‑service providers, and any organization that stores code or configuration files in public or semi‑public repositories.
Recommended Actions
- Deploy organization‑wide secret‑scanning pipelines (pre‑commit, CI/CD, and post‑commit) covering all credential types.
- Enforce automatic credential rotation and revocation for any secret that appears in source control.
- Maintain immutable logs of secret‑scan results and remediation steps to satisfy audit‑readiness requirements.
- Periodically audit repository histories for legacy secrets and remediate them.
Source: BleepingComputer
Technical Notes
- 10 % of the working credentials were older than 6.3 years; the oldest dated to 2009.
- Push Protection blocks only certain patterns; 51.8 % of live credentials fell outside its coverage (e.g., DB connection strings, Google API keys).
- Exposure density rose from 3.72 to 11.62 secrets per million files between 2015 and 2025.
Source: BleepingComputer