TruffleHog is a tool tracked across 23 threat clusters and 34 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity June 21, 2026.
TruffleHog is an open-source security tool that searches Git repositories and their history for exposed secrets, such as API keys, tokens, and credentials. By scanning content and history for high-entropy strings and patterns, it helps defenders detect credential leakage across codebases and cloud tooling, highlighting a persistent risk in software supply chains.
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A cybersecurity researcher discovered 39 exposed Algolia admin API keys across various open source documentation sites. The keys, which were supposed to be read-only, had full permissions, allowing potential attackers…
In early 2026, a surge in phishing attacks utilizing Amazon Simple Email Service (SES) has been reported, exploiting exposed AWS Identity and Access Management (IAM) access keys. Attackers leverage this trusted email…
Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…
Telus Digital, a Canadian telecommunications and BPO provider, has confirmed a significant data breach involving the ShinyHunters hacking group. The attackers claim to have stolen approximately 1 petabyte of data,…
Tyler Robert Buchanan, a 24-year-old from Scotland, pleaded guilty in the U.S. to charges of conspiracy to commit wire fraud and aggravated identity theft, linked to a scheme that stole at least $8 million in…
A study analyzing 10 million websites has uncovered nearly 2,000 exposed API credentials across 10,000 webpages. Researchers from Stanford, led by Nurullah Demir, utilized the tool TruffleHog to identify 1,748 valid…
A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…