Cyber Security News

39M Secret API Keys & Credentials Leaked from GitHub – New Tools to Revamp Security

GitHub has revealed that over 39 million secrets were leaked across its platform in 2024 alone, prompting the company to launch new security tools to combat this persistent threat. 

The exposed secrets include API keys, credentials, tokens, and other sensitive authentication data that could give attackers unauthorized access to critical systems and services.

According to GitHub’s latest security disclosures, several secrets are blocked with push protection on the platform every minute. 

Despite these preventive measures, secret leaks remain one of the most common and preventable causes of security incidents in the developer ecosystem.

The Persistent Threat of Secret Leaks

As development velocity increases with modern tooling, the rate of accidentally exposed secrets has similarly accelerated.

“Most software today depends on secrets credentials, API keys, tokens that developers handle dozens of times a day,” explains Erin Havens, a GitHub security expert. 

“These secrets are often accidentally exposed. Less intuitively, a large number of breaches come from well-meaning developers who purposely expose a secret”.

Security researchers note that even seemingly “low-risk” secrets can give attackers a foothold to move laterally to higher-value assets within an organization’s infrastructure. 

The problem is particularly concerning as research indicates accidental exposure mistakes, such as inadvertently publicizing private repositories, reached record levels in 2024.

New Security Tools Unveiled

In response to these challenges, GitHub has announced several significant security enhancements:

Standalone Secret Protection

GitHub has launched Secret Protection and Code Security as standalone products, making advanced security features more accessible to development teams of all sizes. 

Previously, these tools were only available as part of larger security suites, putting them out of reach for many organizations.

Organization-Wide Secret Scanning

A free, organization-wide secret scan tool has been introduced to help teams identify and reduce exposure. 

This point-in-time scanning feature covers all repositories, public, private, internal, and archived, providing comprehensive visibility into potential secret leaks without requiring the purchase of additional services.

Advanced Security for GitHub Team Organizations

GitHub has extended its Advanced Security features to GitHub Team organizations, democratizing access to security tools previously limited to Enterprise customers. 

This change allows smaller development teams to leverage GitHub’s security features without costly plan upgrades.

Industry-Leading Detection Capabilities

GitHub’s secret scanning technology outperforms alternatives with a precision score of 75%, compared to the next best solution’s 46%. 

The platform achieves this accuracy through partnerships with hundreds of token issuers, including AWS, Google Cloud Platform, Meta, and OpenAI.

The company has also integrated GitHub Copilot to detect unstructured secrets like passwords with extremely low false positive rates, utilizing AI to enhance security scanning capabilities.

Developer Recommendations

Security experts recommend the following best practices for secret management:

  • Implement push protection to prevent secrets from being committed.
  • Follow the principle of least privilege when creating credentials.
  • Regularly rotate secrets to limit exposure windows.
  • Automate secret management to minimize human interaction.
  • Adopt continuous monitoring solutions for detecting exposures.

“The easiest way to protect yourself from leaked secrets is not to have any in the first place,” notes Havens. 

“Push protection, our built-in solution is the simplest way to block secrets from accidental exposure.”

With these new tools, GitHub aims to significantly reduce the 39 million annual secret leaks, providing developers with accessible and effective security solutions for organizations of every size.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago