500,000 Active Credentials Left Exposed on GitHub
Truffle Security has discovered over half a million active unique credentials exposed in public GitHub repositories.
A total of 1,103,438 exposed credentials were discovered through the scanning of 224 million public GitHub repositories in August 2025.
At the end of July 2026, the security firm tested the credentials against their services and found that 543,699 of them were still active.
The oldest is an AWS key that was committed in 2009 and has remained untouched since. The median exposure window across the set is 784 days.
“2,636 live credentials come from files last modified before 2015. A quarter of everything we found is older than four years,” Truffle Security says.
The most concerning part is that nearly half of the credentials were pushed to the public repositories after GitHub enabled free alerts and default push protections to prevent the inadvertent exposure.
Advertisement. Scroll to continue reading.
“245,959 credentials predate...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE