More than 543,000 live credentials remain exposed on GitHub
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, October 1st, 2026.
An analysis found five hundred forty three thousand six hundred ninety nine unique working credentials exposed across public GitHub content. Researchers scanned 224 million repositories and more than 58 billion files. The median credential remained publicly accessible for 784 days, showing that many secrets survive far beyond the original development mistake. About fifty one point eight percent of the live credentials belonged to categories that GitHub’s default Push Protection doesn’t block. The control still made a measurable difference within the categories it does cover, where the exposure rate fell by fifty three percent after it became the default.
Removing a file isn’t enough because repository history, forks, and other copies may preserve the secret. Exposed cloud keys, service accounts, and database connection strings can give attackers access that looks legitimate and may blend into normal activity. Leaders should view prevention controls as one layer, not a replacement for credential inventory, expiration, and rotation. Defenders should continuously scan repository history and forks, revoke exposed credentials, and review associated activity for misuse. Long-lived credentials can turn a simple publishing mistake into durable cloud and supply-chain exposure. Automate secret detection and expiration, then immediately rotate every credential found in public code or repository history.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.