GitLab Scan Reveals Over 17,000 Exposed Secrets in Public Repositories

GitLab Scan Reveals Over 17,000 Exposed Secrets in Public Repositories

First seen 28 Nov 2025, 18:37 UTC News.YcombinatorBleepingcomputer 26.3

Article Content

Browse articles
ThreatCluster

A security engineer scanned 5.6 million public GitLab repositories and found more than 17,000 exposed secrets, including sensitive credentials like API keys and passwords. The findings were made using the TruffleHog tool, and the researcher, Luke Marshall, earned over $9,000 in bounties for responsible disclosure of these vulnerabilities.