BleepingComputer reports that more than 543,000 credentials were exposed in public GitHub repositories and were still valid in July. That turns a familiar secret-leak problem into an immediate access risk, because the accounts behind those keys and tokens could still be used.
The issue is not the repository itself but the standing credential it contains. If a leaked API key, password, or token still works, an attacker who finds it can use it against the connected SaaS, cloud, or CI system just as the owner would, which can mean account takeover or unauthorized actions without touching the codebase again.
For teams that share code on GitHub, the exposure sits with the downstream accounts and services, not just the commit history. Secret scanning can flag the repo, but it does not by itself remove the live access those credentials still grant.
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.