trufflesecurity.com Over 543,000 Valid Credentials Exposed on GitHub Despite Security Measures
Article Content
- •Over 543,000 valid credentials were found in public GitHub repositories.
- •The oldest credential exposed dates back to 2009, with a median exposure time of 784 days.
- •Push Protection has not effectively prevented the exposure of many credential types.
Truffle Security reported that over 543,000 valid credentials were found in public GitHub repositories, still active as of July 2026. The analysis covered 224 million repositories and 58 billion files, revealing that the median credential had been publicly accessible for 784 days, with the oldest dating back to 2009. Despite GitHub's Push Protection feature aimed at preventing accidental leaks, 36.8% of the exposed credentials were uploaded after this feature was enabled by default in February 2024. The study highlighted that 51.8% of the active credentials fell into categories not recognized by Push Protection. Truffle's findings indicate a significant increase in credential exposure, with the number of working credentials more than doubling since a previous scan in August 2025. The report emphasizes the need for immediate action to rotate exposed credentials and clean up repositories.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What types of credentials were exposed?
How long were the credentials publicly accessible?
What should developers do about exposed credentials?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…