Breaches · 3h ago

Public GitHub Secrets Stayed Live for Months

BleepingComputer reports that more than 543,000 credentials were exposed in public GitHub repositories and were still valid in July. That turns a familiar secret-leak problem into an immediate access risk, because the accounts behind those keys and tokens could still be used.

The issue is not the repository itself but the standing credential it contains. If a leaked API key, password, or token still works, an attacker who finds it can use it against the connected SaaS, cloud, or CI system just as the owner would, which can mean account takeover or unauthorized actions without touching the codebase again.

For teams that share code on GitHub, the exposure sits with the downstream accounts and services, not just the commit history. Secret scanning can flag the repo, but it does not by itself remove the live access those credentials still grant.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-01

Editions

Related stories