Over 543,000 valid credentials exposed in public GitHub repositories
Truffle Security scanned an LLM training dataset of 224 million repos and 58 billion files and pulled out 543,699 credentials that still worked. The bit that stings: median exposure was 784 days, and 36.8% were pushed after GitHub turned Push Protection on by default. npm had 1 valid token out of 101,886; Google Cloud had 69,041 of 126,963 still working. Detection isn’t the gap, rotation and expiry are.