500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
The latest developments from the last 30 days, newest first.
500,000 Active Credentials Left Exposed on GitHub
Basis: Reporting by SecurityWeek
Over 543,000 valid credentials exposed in public GitHub repositories
Basis: Reporting by BleepingComputer