Menu

Post image 1
Post image 2
1 / 2
0

39 Million Secrets Leaked on GitHub. Yours Could Be Next.

DEV Community·Fernando Rodriguez·about 1 month ago
#AR4ijSnw
Reading 0:00
15s threshold

5 minutes. That's how long it took. A security researcher publishes an AWS access key on a public GitHub repository. They do it on purpose, as an experiment. Five minutes later, someone was already using it to mine cryptocurrency. Five. Minutes. There are bots scanning GitHub 24/7 looking for exactly that: exposed credentials. And they're fast. Much faster than you realizing you screwed up. The numbers are scary According to GitHub, 39 million secrets were leaked in public repositories in 2024. A 67% increase from the previous year. GitGuardian, which specializes in scanning exactly this, found 23.7 million new secrets just in public repos. And the worst part: 70% of secrets detected in 2022 were still active in 2024. Two years later. Still working. Waiting for someone to use them. It's not just random people Toyota had AWS credentials exposed on GitHub that gave access to their vehicle telematics system. Pearson lost data because someone left a GitLab token in a configuration file.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More