Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Over 500,000 Active Credentials Found on GitHub

Over 500,000 Active Credentials Found on GitHub

Posted on October 1, 2026 By CWS

Truffle Security has unveiled that more than 500,000 active credentials are publicly accessible in GitHub repositories. This discovery highlights significant vulnerabilities in securing sensitive information.

Vast Scope of Exposure

In August 2025, a thorough examination of 224 million public repositories on GitHub revealed a startling 1,103,438 exposed credentials. By July 2026, the firm verified that 543,699 of these were still valid and operational.

Among the exposed credentials, an AWS key dating back to 2009 remained active, illustrating long-term security oversights. The median duration for which the credentials were exposed was 784 days, indicating persistent vulnerabilities in data protection.

Challenges in Credential Management

A significant portion of these credentials were found in files last updated before 2015, with 2,636 still active. Approximately 25% of the exposed credentials are over four years old, suggesting a need for regular audits and updates.

Despite GitHub’s efforts to mitigate exposure through free alerts and default push protections, nearly half of these credentials were added to repositories after such measures were implemented. This raises concerns about the effectiveness and adoption of these security practices.

Efforts and Future Considerations

GitHub’s secret-scanning initiative aims to notify providers of exposed tokens for revocation. However, the lack of mandatory revocation results in many credentials remaining active. Notably, Google Cloud service accounts, MongoDB connection strings, and Google API keys were predominant among exposed credentials.

Truffle Security highlights that the persistence of these active tokens is not due to a lack of preventive measures but rather the absence of effective revocation processes. This emphasizes the need for improved collaboration between GitHub and service providers to bolster security protocols.

As the digital landscape evolves, ensuring robust credential management is crucial for protecting sensitive information. Continuous monitoring and proactive measures are essential for mitigating risks associated with exposed credentials.

Security Week News Tags:API keys, AWS, Credentials, data exposure, GitHub, Google Cloud, public repositories, secret scanning, Security, Truffle Security

Post navigation

Previous Post: Urgent Fixes Issued for Cisco SD-WAN Critical Flaw
Next Post: MikroTik RouterOS Vulnerability Exposes Critical Risks

Related Posts

Cyberattack Unlikely in Communications Failure That Grounded Flights in Greece Cyberattack Unlikely in Communications Failure That Grounded Flights in Greece Security Week News
Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin Security Week News
New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data Security Week News
Chrome 149 Update Fixes Record 429 Security Flaws Chrome 149 Update Fixes Record 429 Security Flaws Security Week News
Critical Linux Kernel Bug Allows Root Access Critical Linux Kernel Bug Allows Root Access Security Week News
ShinyHunters Allegedly Breaches Council of Europe ShinyHunters Allegedly Breaches Council of Europe Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark