Cyber

Over 543,000 valid credentials exposed in public GitHub repositories

According to BleepingComputer, more than 543,000 credentials exposed in public GitHub repositories remained valid in July despite platform security measures.

·1 min read
Over 543,000 valid credentials exposed in public GitHub repositories

Software supply chain security faces ongoing challenges as new data reveals persistent vulnerabilities in repository management. In July, more than 543,000 credentials and sensitive keys left exposed in public GitHub repositories were found to still be valid.

As reported by BleepingComputer, these exposures occurred despite the platform's continuous implementation of security features designed to prevent accidental leaks of sensitive data. Developers frequently commit API keys, passwords, and tokens during testing or due to oversight, leaving them visible to anyone.

Leaving such credentials exposed poses severe cybersecurity risks. Threat actors routinely employ automated scrapers to comb public repositories for valid secrets, enabling them to gain unauthorized access to corporate networks, cloud services, and user accounts.

For the tech ecosystem in Uzbekistan and neighboring regions, this incident highlights the critical need for robust secure coding practices. Local developers and IT companies engaging with international standards must prioritize strict repository access controls and secret scanning protocols.

Industry experts recommend integrating automated secret detection tools into the development pipeline before code ever reaches public repositories. Furthermore, organizations should maintain a strict incident response plan to immediately revoke and rotate any credentials found outside secure environments.

#GitHub#Kiberxavfsizlik#Dasturlash#API#Xavfsizlik#BleepingComputer

Related articles