Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Over 543,000 Valid Credentials Exposed in Public GitHub Repositories

Truffle Security identified more than half‑a‑million active credentials hidden in public GitHub repos, many remaining valid for years. This highlights the need for continuous secret‑monitoring and auditable credential‑rotation controls to satisfy compliance and audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
bleepingcomputer.com

Over 543,000 Valid Credentials Exposed in Public GitHub Repositories

What Happened – Researchers at Truffle Security scanned 224 million public GitHub repositories and uncovered 543,699 unique, still‑working credentials. The median exposure time was 784 days, and 36.8 % of the live secrets appeared after GitHub’s Push Protection was enabled by default.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of code repositories is essential; a control‑assurance program should capture secret‑leak events in near‑real time and retain evidence for audit.
  • Credential rotation and revocation policies must be enforceable and auditable, providing a defensible trail that demonstrates due diligence.
  • Automated secret‑detection tools (e.g., Push Protection) reduce risk, but gaps remain—control owners need to map coverage to their risk register and supplement with supplemental scans.

Who Is Affected – Software developers, SaaS vendors, cloud‑service providers, and any organization that stores code or configuration files in public or semi‑public repositories.

Recommended Actions

  • Deploy organization‑wide secret‑scanning pipelines (pre‑commit, CI/CD, and post‑commit) covering all credential types.
  • Enforce automatic credential rotation and revocation for any secret that appears in source control.
  • Maintain immutable logs of secret‑scan results and remediation steps to satisfy audit‑readiness requirements.
  • Periodically audit repository histories for legacy secrets and remediate them.

Source: BleepingComputer

Technical Notes

  • 10 % of the working credentials were older than 6.3 years; the oldest dated to 2009.
  • Push Protection blocks only certain patterns; 51.8 % of live credentials fell outside its coverage (e.g., DB connection strings, Google API keys).
  • Exposure density rose from 3.72 to 11.62 secrets per million files between 2015 and 2025.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →