All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Security Researcher Finds 17,000+ Live Secrets in 5.6 Million Public GitLab Repositories

By

adrianwaj

6mo ago· 7 min readenInsight

Summary

A security researcher scanned 5.6 million public GitLab repositories using TruffleHog and discovered over 17,000 verified live secrets, earning over $9,000 in bug bounties through responsible disclosure. The research reveals significant security risks in public code repositories and demonstrates the effectiveness of automated scanning tools for identifying exposed credentials.

Key quotes

· 4 pulled
I scanned every public GitLab Cloud repository (~5.6 million) with TruffleHog, found over 17,000 verified live secrets, and earned over $9,000 in bounties along the way.
This guest post by Security Engineer Luke Marshall was developed through Truffle Security's Research CFP program.
Luke specializes in investigating exposed secrets across open-source ecosystems, a path that led him into bug bounty work and responsible disclosure.
This is the last blog post in a two-part series exploring secrets exposed in popular Git platforms.
Snippet from the RSS feed
I scanned every public GitLab Cloud repository (~5.6 million) with TruffleHog, found over 17,000 verified live secrets, and earned over $9,000 in bounties along the way.

You might also wanna read