GitHub has revealed that over 39 million secrets were leaked across its platform in 2024 alone, prompting the company to launch new security tools to combat this persistent threat.
The exposed secrets include API keys, credentials, tokens, and other sensitive authentication data that could give attackers unauthorized access to critical systems and services.
According to GitHub’s latest security disclosures, several secrets are blocked with push protection on the platform every minute.
Despite these preventive measures, secret leaks remain one of the most common and preventable causes of security incidents in the developer ecosystem.
As development velocity increases with modern tooling, the rate of accidentally exposed secrets has similarly accelerated.
“Most software today depends on secrets credentials, API keys, tokens that developers handle dozens of times a day,” explains Erin Havens, a GitHub security expert.
“These secrets are often accidentally exposed. Less intuitively, a large number of breaches come from well-meaning developers who purposely expose a secret”.
Security researchers note that even seemingly “low-risk” secrets can give attackers a foothold to move laterally to higher-value assets within an organization’s infrastructure.
The problem is particularly concerning as research indicates accidental exposure mistakes, such as inadvertently publicizing private repositories, reached record levels in 2024.
In response to these challenges, GitHub has announced several significant security enhancements:
GitHub has launched Secret Protection and Code Security as standalone products, making advanced security features more accessible to development teams of all sizes.
Previously, these tools were only available as part of larger security suites, putting them out of reach for many organizations.
A free, organization-wide secret scan tool has been introduced to help teams identify and reduce exposure.
This point-in-time scanning feature covers all repositories, public, private, internal, and archived, providing comprehensive visibility into potential secret leaks without requiring the purchase of additional services.
GitHub has extended its Advanced Security features to GitHub Team organizations, democratizing access to security tools previously limited to Enterprise customers.
This change allows smaller development teams to leverage GitHub’s security features without costly plan upgrades.
GitHub’s secret scanning technology outperforms alternatives with a precision score of 75%, compared to the next best solution’s 46%.
The platform achieves this accuracy through partnerships with hundreds of token issuers, including AWS, Google Cloud Platform, Meta, and OpenAI.
The company has also integrated GitHub Copilot to detect unstructured secrets like passwords with extremely low false positive rates, utilizing AI to enhance security scanning capabilities.
Security experts recommend the following best practices for secret management:
“The easiest way to protect yourself from leaked secrets is not to have any in the first place,” notes Havens.
“Push protection, our built-in solution is the simplest way to block secrets from accidental exposure.”
With these new tools, GitHub aims to significantly reduce the 39 million annual secret leaks, providing developers with accessible and effective security solutions for organizations of every size.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…