Public GitHub repositories valid credential exposure
Data Leak
Summary
Hide ▲
Show ▼
More than 543,699 credentials exposed in public GitHub repositories were still valid in July, leaving a large pool of reusable secrets accessible to anyone who found them. The exposed material appeared repeatedly across more than 1.1 million files and repositories, including copies in forks. The median exposure window was 784 days, and some working credentials dated back to 2009. Push Protection reduced some accidental leaks, but it does not revoke secrets that were already exposed.
Related Happenings
Developers at over 300 organizations customer data exposed after GitHub Glow breach
Data Leak
H score41
First: 30.09.2026 14:30
Last: 30.09.2026 14:30
Sources 1
About this happening:
A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screen...
Developers at over 300 organizations customer data exposed after GitHub Glow breach
Data LeakAbout this happening: A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screen...
GitHub App private keys leaked in public code
Data Leak
H score50
First: 23.09.2026 18:00
Last: 23.09.2026 18:00
Sources 1
About this happening:
GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization con...
GitHub App private keys leaked in public code
Data LeakAbout this happening: GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization con...
TeamPCP supply-chain credential and data leak
Data Leak
H score59
First: 27.08.2026 16:31
Last: 27.08.2026 16:31
Sources 1
About this happening:
A TeamPCP-linked supply-chain leak exposed half a million credentials and at least 300GB of data, putting over a thousand organizations worldwide at risk of downstream...
TeamPCP supply-chain credential and data leak
Data LeakAbout this happening: A TeamPCP-linked supply-chain leak exposed half a million credentials and at least 300GB of data, putting over a thousand organizations worldwide at risk of downstream...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceAbout this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
Single organization's private GitHub repository cloned after confirmed access
Data Leak
H score12
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Single organization's private GitHub repository cloned after confirmed access
Data LeakAbout this happening: Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Timeline
-
30.09.2026 21:08 2 articles · 3h ago
Truffle Security reports 543,699 valid credentials in public GitHub repositories
Initial DisclosureTruffle Security reported that 543,699 unique credentials remained valid in public GitHub repositories in July, with a median public exposure window of 784 days and about 10% older than 6.3 years; 199,843 of the credentials had been exposed after GitHub enabled Push Protection for all users in February 2024, and protected categories saw a 53% reduction after the feature became default. The findings also note that Push Protection was introduced for Advanced Security users in April 2022 and made available for public repositories in May 2023, but it does not revoke credentials that were already exposed.
Show sources
- Over 543,000 valid credentials exposed in public GitHub repositories — www.bleepingcomputer.com — 30.09.2026 21:08
- Over 543,000 valid credentials exposed in public GitHub repositories — www.bleepingcomputer.com — 30.09.2026 21:08