Find notable cyber news and cases, enriched with sources, timelines, and signals.

GitHub App private keys leaked in public code

Data Leak
First reported
Last updated
Happening score
H score 50
1 unique sources, 1 articles

Summary

Hide ▲

GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization controls. The research found that 474 leaked keys still authenticated as 440 distinct Apps, and some grants included organization administration and workflow control. Because these keys do not expire until manually deleted, the exposure created an ongoing access risk rather than a one-time leak.

Related Happenings

CISA recommends continuous secrets scanning and stronger key management after GitHub leak

Defensive Guidance
H score26 First: 13.07.2026 18:03 Last: 13.07.2026 18:03 Sources 1

About this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...

GitHub Agentic Workflows indirect prompt injection security flaw

Vulnerability
H score27 First: 07.07.2026 17:04 Last: 07.07.2026 17:04 Sources 1

About this happening: GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...

Visual Studio Code VS Code token-theft zero-day security flaw

Vulnerability
H score44 First: 03.06.2026 09:50 Last: 03.06.2026 09:50 Sources 1

About this happening: A Visual Studio Code (VS Code) zero-day lets attackers steal GitHub OAuth tokens by abusing the editor's sandboxed webview message-passing system. The flaw is especial...

Latest development: 03.06.2026 15:58

Microsoft has acknowledged a Visual Studio Code vulnerability that can let an attacker use a crafted link and malicious webview message-passing to steal a victim's GitHub OAuth token via GitHub.dev, and said it is working on a fix; Microsoft also said the issue does not affect VS Code Desktop.

Megalodon GitHub CI/CD supply-chain campaign

Campaign
H score50 First: 22.05.2026 14:55 Last: 22.05.2026 14:55 Sources 1

About this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...

Rwl.angular-console (Nx Console) hit by network compromise

Incident
H score41 First: 19.05.2026 10:49 Last: 19.05.2026 10:49 Sources 1

About this happening: The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...

Timeline

  1. 23.09.2026 18:00 2 articles · 1d ago

    GitHub App private keys leaked in public code

    Initial Disclosure

    GitGuardian identified GitHub App private keys in public code that still authenticated to GitHub's API. The first pass showed that some leaked keys could read private repositories, administer organizations, and control workflows.

    Show sources