logo

2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

ID: f9af71cc-7193-5fcb-8e2b-39894419a078

STIX ID: report--f9af71cc-7193-5fcb-8e2b-39894419a078

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Guillaume Valadon

...
...

GitGuardian and Google researchers mapped leaked private keys found on GitHub and DockerHub to Certificate Transparency logs, linking about one million leaked keys to 140,000 certificates and identifying 2,600 currently valid TLS certificates (including many protecting high-value organizations). Their disclosure campaign contacted thousands of owners and CAs, achieving large-scale remediation but revealing low direct response rates, minimal revocation via CRL/OCSP, frequent key reuse across renewals, and systemic failures that leave sites vulnerable to impersonation, MitM, and decryption of past traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.