Breaches · 3h ago
BleepingComputer reports that more than 543,000 credentials were exposed in public GitHub repositories and were still valid in July. That turns a familiar secret-leak problem into an immediate access risk, because the accounts behind those keys and tokens could still be used.
The issue is not the repository itself but the standing credential it contains. If a leaked API key, password, or token still works, an attacker who finds it can use it against the connected SaaS, cloud, or CI system just as the owner would, which can mean account takeover or unauthorized actions without touching the codebase again.
For teams that share code on GitHub, the exposure sits with the downstream accounts and services, not just the commit history. Secret scanning can flag the repo, but it does not by itself remove the live access those credentials still grant.
2 sources covering this story
500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default.
Over 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
Part of the PlainSec briefing for 2026-10-01