Over 543,000 Valid Credentials Exposed on GitHub
🔒 Truffle Security scanned 224 million GitHub repositories and found 543,699 unique credentials that remained valid in July, appearing across more than 1.1 million files and forks. The median exposure time for a credential was 784 days, with about 10% older than 6.3 years and some dating back to 2009. GitHub's Push Protection reduced exposures in covered categories by 53%, but many secrets (like DB strings and Google API keys) remain outside its default scope. Researchers urge immediate rotation, history cleanup, and automated expiration of secrets.
