Bleepingcomputer
GitLab Scan Reveals Over 17,000 Exposed Secrets in Public Repositories
First seen 28 Nov 2025, 18:37 UTC
•
•26.3
Export
Article Content
Browse articles
A security engineer scanned 5.6 million public GitLab repositories and found more than 17,000 exposed secrets, including sensitive credentials like API keys and passwords. The findings were made using the TruffleHog tool, and the researcher, Luke Marshall, earned over $9,000 in bounties for responsible disclosure of these vulnerabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
39 Exposed Algolia Admin Keys Threaten Major Open Source Projects
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
Amazon SES Phishing Attacks Bypass Email Security Measures
768 Leaked AWS Keys Grant Full Admin Access to Corporate Accounts