Half a million GitHub secrets are still live and unrevoked

Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.

The Latest

Breaking News and Alerts

Helpful AI agents quietly posted 13,000 company screenshots to GitHub

Glow Security traced thousands of internal images to AI coding agents that routed private screenshots through public repos.

Spotlight

Cybersecurity Profiles and Stories

Pentagon records office admits a nine-month intruder access

The Defense Manpower Data Center left unencrypted records open to intruders for nine months.

A rogue MCP server can walk off with your OAuth tokens

A malicious MCP server can redirect a client's OAuth handshake and pocket the secrets.

Microsoft ties a quiet intrusion toolkit to the Daemon Tools breach

The toolkit let intruders hold ground inside telecom, university and government networks.

Apple patches a zero-day used in surgically targeted attacks

An out-of-bounds write in Apple's drawing engine was aimed at a targeted few.

Features

Research and Thought Leadership