Public GitLab repositories exposed more than 17,000 secrets
ID: 619f4082-ee86-5261-8f96-51ba718cb102
STIX ID: report--619f4082-ee86-5261-8f96-51ba718cb102
Feed Name: Bleeping Computer
A researcher scanned 5.6 million public GitLab Cloud repositories using TruffleHog and AWS automation, identifying 17,430 live exposed secrets across 2,804 domains (notably GCP credentials, MongoDB keys, Telegram bot tokens, OpenAI keys and some GitLab keys). The report covers the scanning methodology, notification of affected parties (leading to many revocations and some bounties), and notes that an undisclosed number of secrets remain exposed; it does not report confirmed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
