39M secrets exposed: GitHub rolls out new security tools

This post was originally published on Security Affairs. It can be found here.

39 Million Secrets Leaked on GitHub in 2024

GitHub found 39M secrets leaked in 2024 and launched new tools to help developers and organizations secure sensitive data in code.

Microsoft-owned code hosting platform GitHub announced the discovery of 39 million secrets leaked in 2024. The exposure of this sensitive information poses a serious risk to organizations, as malicious actors are ready to exploit it in attacks. Developers frequently expose secrets like API keys, often underestimating the risk. Attackers exploit even “low-risk” leaks for lateral movement. Storing secrets in git history increases vulnerability, and accidental public exposures hit record highs in 2024.

“To give you an idea of the scope of the problem, more than 39 million secrets were leaked across GitHub in 2024 alone. Every minute GitHub blocks several secrets with push protection.” reads the report published by GitHub. “Still, secret leaks remain one of the most common—and preventable—causes of security incidents. As we develop code faster than ever previously imaginable, we’re leaking secrets faster than ever, too.”

The company launched new tools to help developers and organizations secure sensitive data in their code.

GitHub launches new Advanced Security features, including standalone Secret Protection and Code Security, support for GitHub Team orgs, and free secret scanning. Secret Protection is free for public repositories.

The company now offers standalone security add-ons for Team organizations, eliminating the need for Enterprise upgrades. To prevent leaks, GitHub enables Team and Enterprise users to run secret risk assessments across all repositories, enhancing security.

Secret Protection is free for public repositories. The company states that identifying exposed secrets is crucial.

“The secret risk assessment is a point-in-time scan leveraging our scanning engine for organizations, covering all repositories–public, private, internal, and even archived–and can be run without purchase. The point-in-time scan provides clear insights into the exposure of your secrets across your organization, along with actionable steps to strengthen your security and protect your code.” concludes the report. “In order to lower barriers for organizations to use and benefit from the feature, no specific secrets are stored or shared.” GitHub notes.

GitHub Advanced Security introduces major updates to enhance secret protection and code security. Now available as standalone products, these tools no longer require a full GitHub Advanced Security license, making them more accessible to smaller teams.

GitHub has also enhanced push protection with delegated bypass controls, allowing organizations to define who can override security measures, adding policy-level enforcement. AI-powered secret detection using GitHub Copilot improves accuracy by identifying unstructured secrets like passwords, reducing false positives.

To further strengthen security, GitHub has partnered with cloud providers like AWS, Google Cloud, and OpenAI to improve secret detection and response times.

The Microsoft-owned company also recommends best practices such as enabling Push Protection, eliminating hardcoded secrets, and using secret managers, environment variables, or CI/CD-integrated tools to reduce human error and exposure risks.

These updates aim to make security more accessible and improve secret management across repositories.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, secure coding)

This post was originally published on this site

Forum Search

Partners & Sponsors
  • University of Baltimore
  • Towson University
  • Bureau of Justice Assistance
  • National Science Foundation
LATEST FORUM POSTS
Test post2

Test Post2

By Demo User12, 1 year ago

Finding internships

Hello, Has anyone here secured any forensic related internships for 2024? I'm collecting some data and wanted to know what...

By AP Malla, 1 year ago

Beginner network forensic investigation

How should I approach network forensic? Would you recommend learning tools like WireShark?

By AP Malla, 1 year ago

Cyber Forensic Employment: High level guidelines

Understand the Basics: Know the Field: Cyber forensics involves investigating digital crimes, analyzing electronic data, and recovering hidden, deleted, or...

By AP Malla, 1 year ago

LATEST POSTS