TruffleHog - Tool

Threat entity extracted from intelligence sources

Frequency
34
occurrences
First Seen
November 10, 2025
Last Seen
June 21, 2026

TruffleHog is a tool tracked across 23 threat clusters and 34 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity June 21, 2026.

Overview

TruffleHog is an open-source security tool that searches Git repositories and their history for exposed secrets, such as API keys, tokens, and credentials. By scanning content and history for high-entropy strings and patterns, it helps defenders detect credential leakage across codebases and cloud tooling, highlighting a persistent risk in software supply chains.

Related Threat Clusters

  • CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices

    On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…

    3 articles · Updated April 26, 2026
  • Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise

    AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…

    30 articles · Updated April 1, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    696 articles · Updated April 29, 2026
  • 39 Exposed Algolia Admin Keys Threaten Major Open Source Projects

    A cybersecurity researcher discovered 39 exposed Algolia admin API keys across various open source documentation sites. The keys, which were supposed to be read-only, had full permissions, allowing potential attackers…

    2 articles · Updated March 13, 2026
  • Amazon SES Phishing Attacks Bypass Email Security Measures

    In early 2026, a surge in phishing attacks utilizing Amazon Simple Email Service (SES) has been reported, exploiting exposed AWS Identity and Access Management (IAM) access keys. Attackers leverage this trusted email…

    8 articles · Updated May 4, 2026
  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026
  • Telus Digital Confirms Massive Data Breach by ShinyHunters Group

    Telus Digital, a Canadian telecommunications and BPO provider, has confirmed a significant data breach involving the ShinyHunters hacking group. The attackers claim to have stolen approximately 1 petabyte of data,…

    18 articles · Updated March 12, 2026
  • Scattered Spider Hacker Pleads Guilty to $8 Million Crypto Theft

    Tyler Robert Buchanan, a 24-year-old from Scotland, pleaded guilty in the U.S. to charges of conspiracy to commit wire fraud and aggravated identity theft, linked to a scheme that stole at least $8 million in…

    14 articles · Updated April 20, 2026
  • Exposed API Credentials Found on Thousands of Websites

    A study analyzing 10 million websites has uncovered nearly 2,000 exposed API credentials across 10,000 webpages. Researchers from Stanford, led by Nurullah Demir, utilized the tool TruffleHog to identify 1,748 valid…

    2 articles · Updated March 27, 2026
  • Stolen Gemini API Key Leads to $82K in Unauthorized Charges

    A three-person development team in Mexico faces financial ruin after a stolen Google Cloud API key resulted in $82,314.44 in unauthorized charges within 48 hours. The key was compromised between February 11 and 12,…

    3 articles · Updated March 4, 2026

Recent Intelligence Reports

  • Salesloft Drift Breach Recap — www.anomali.com · June 21, 2026
  • Data Theft Salesforce Instances Via Salesloft Drift — cloud.google.com · June 21, 2026
  • 5 Vulnerabilities in Every Vibe-Coded App — Strobes.Co · May 29, 2026
  • TeamPCP releases 'vibe coded' Shai-Hulud source code, issues challenge — Scworld · May 15, 2026
  • Amazon SES increasingly abused in phishing to evade detection — Bleepingcomputer · May 4, 2026
  • “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security — Securelist · May 4, 2026
  • Unc3944 Sms Phishing Sim Swapping Ransomware — www.mandiant.com · April 28, 2026
  • CISA KEV: 4 Exploited CVEs — SimpleHelp, Samsung MagicINFO, D-Link — Abhs.In · April 25, 2026

CVSS v3.1 Breakdown