Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
GitHub just found 39 million leaked secrets, announced paid tools

GitHub just found 39 million leaked secrets, announced paid tools

by Tekmono Editorial Team
03/04/2025
in News
Share on FacebookShare on Twitter

GitHub is doubling down on security after its systems detected a staggering 39 million secrets—API keys, passwords, and other credentials—leaked in repositories during 2024. This exposure puts both users and organizations at considerable risk, prompting significant upgrades to the Advanced Security platform.

According to GitHub’s recent report, these leaked secrets were identified using its secret scanning service, a feature designed to detect sensitive information within repositories.

“Secret leaks remain one of the most common—and preventable—causes of security incidents,” GitHub stated, emphasizing the urgency of the situation. The company notes that the pace of code development is matched by an equally rapid increase in secret leaks.

Related Reads

The Witcher 3 expansion Songs of the Past to be revealed at Gamescom 2026

Snapdragon 4 Gen 6 leak hints at on-device AI capabilities for budget phones

Deezer reports over half of new music uploads are fully AI-generated

NVIDIA’s Vera CPU outperforms x86 chips with 6x speed and 40% lower latency

This surge in leaks persists despite GitHub’s introduction of “Push Protection” in April 2022, which became a default feature on all public repositories in February 2024.

GitHub attributes the ongoing leaks to developers prioritizing convenience when handling secrets during commits, as well as accidental repository exposure through git history.

To address these vulnerabilities, GitHub has announced several new measures and enhancements to its Advanced Security platform:

GitHub is now offering its security products as standalone purchases for enterprises, allowing development teams to scale security measures more efficiently. Previously, access to secret scanning and push protection required a more extensive (and expensive) suite of security tools. Key changes to GitHub Advanced Security include:

  • Standalone secret protection and code security: These tools are now available separately, removing the requirement for a full GitHub Advanced Security license and making them more accessible for smaller teams.
  • Free organization-wide secret risk assessment: GitHub is providing a complimentary, one-time scan to check all repository types (public, private, internal, and archived) for exposed secrets for all GitHub organizations.
  • Push protection with delegated bypass controls: The enhanced push protection now scans for secrets before code is pushed and allows organizations to define permissions for bypassing the protection, providing policy-level control.
  • Copilot-powered secret detection: GitHub is leveraging AI via Copilot to enhance detection of unstructured secrets like passwords, thereby improving accuracy and reducing false positives.
  • Improved detection via cloud provider partnerships: Through collaborations with providers like AWS, Google Cloud, and OpenAI, GitHub aims to refine secret detectors and accelerate responses to leaks.

Beyond GitHub’s own efforts, the platform is also recommending specific actions users can take to safeguard against secret leaks.

Users are urged to enable Push Protection at the repository, organization, or enterprise level to proactively block secrets before they are pushed to a repository.

GitHub also underscores the importance of minimizing risk by eliminating hardcoded secrets from source code. Instead, it recommends utilizing environment variables, secret managers, or vaults for secure storage.

Another recommendation involves using tools integrated with CI/CD pipelines and cloud platforms for programmatic handling of secrets. This approach aims to reduce human interaction, which can lead to errors and exposure.

Finally, GitHub advises users to consult the ‘Best Practices’ guide to ensure comprehensive end-to-end management of secrets.

Tags: APIcredentialGitHubpasswordsecurity
ShareTweet

You Might Be Interested

The Witcher 3 expansion Songs of the Past to be revealed at Gamescom 2026
News

The Witcher 3 expansion Songs of the Past to be revealed at Gamescom 2026

21/07/2026
Snapdragon 4 Gen 6 leak hints at on-device AI capabilities for budget phones
News

Snapdragon 4 Gen 6 leak hints at on-device AI capabilities for budget phones

21/07/2026
Deezer reports over half of new music uploads are fully AI-generated
News

Deezer reports over half of new music uploads are fully AI-generated

21/07/2026
NVIDIA’s Vera CPU outperforms x86 chips with 6x speed and 40% lower latency
News

NVIDIA’s Vera CPU outperforms x86 chips with 6x speed and 40% lower latency

21/07/2026
Please login to join discussion

Recent Posts

  • The Witcher 3 expansion Songs of the Past to be revealed at Gamescom 2026
  • Snapdragon 4 Gen 6 leak hints at on-device AI capabilities for budget phones
  • Deezer reports over half of new music uploads are fully AI-generated
  • NVIDIA’s Vera CPU outperforms x86 chips with 6x speed and 40% lower latency
  • Microsoft releases Windows 11 Build 26220.8925 with key Start menu and touchpad updates

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.