logo

Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks

ID: f23d1293-278f-5e2c-858e-d977cd2eceea

STIX ID: report--f23d1293-278f-5e2c-858e-d977cd2eceea

Feed Name: Wiz Blog

Threat Score
65/100

Date Published: 2025-11-10

Date Updated: 2026-05-01

...
...

This research analyzes the public and deep GitHub footprints of Forbes AI 50 companies and reports that about 65% had verified secret leaks—API keys, tokens, and credentials found in commit histories, deleted forks, gists, and developer repos. The study describes a 'Depth, Perimeter, and Coverage' methodology to uncover buried exposures, provides example cases (LangChain, ElevenLabs, HuggingFace), highlights disclosure challenges, and recommends mandatory public VCS secret scanning, disclosure preparedness, and expanding secret-type detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.