Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Are We Ready for AI Enshittification? What Happens When the Systems You Trust Suddenly Stop Working

    UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

    Strategic shift pays off as Okta bids to ease agentic AI risk

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      Five Cryptocurrencies That Often Rally Around Christmas

      December 3, 2025

      Why Trump-Backed Mining Company Struggles Despite Bitcoin’s Recovery

      December 3, 2025

      XRP ETFs Extend 11-Day Inflow Streak as $1 Billion Mark Nears

      December 3, 2025

      Why AI-Driven Crypto Exploits Are More Dangerous Than Ever Before

      December 3, 2025

      Bitcoin Is Recovering, But Can It Drop Below $80,000 Again?

      December 3, 2025
    • Technology

      Are We Ready for AI Enshittification? What Happens When the Systems You Trust Suddenly Stop Working

      December 3, 2025

      UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

      December 3, 2025

      Strategic shift pays off as Okta bids to ease agentic AI risk

      December 3, 2025

      Use of digital ID in UK achieves statutory status

      December 3, 2025

      Post Office scandal could widen to thousands more branches after third system appeal

      December 3, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Business Technology»Public GitLab repositories exposed more than 17,000 secrets
    Business Technology

    Public GitLab repositories exposed more than 17,000 secrets

    TechAiVerseBy TechAiVerseNovember 29, 2025No Comments3 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Public GitLab repositories exposed more than 17,000 secrets
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Public GitLab repositories exposed more than 17,000 secrets

    After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains.

    Luke Marshall used the TruffleHog open-source tool to check the code in the repositories for sensitive credentials like API keys, passwords, and tokens.

    The researcher previously scanned Bitbucket, where he found 6,212 secrets spread over 2.6 million repositories. He also checked the Common Crawl dataset that is used to train AI models, which exposed 12,000 valid secrets.

    GitLab is a web-based Git platform used by software developers, maintainers, and DevOps teams to host code, for CI/CD operations, development collaboration, and repository management.

    Marshall used a GitLab public API endpoint to enumerate every public GitLab Cloud repository, using a custom Python script to paginate through all results and sort them by project ID.

    This process returned 5.6 million non-duplicate repositories, and their names were sent to an AWS Simple Queue Service (SQS).

    Next, an AWS Lambda function pulled the repository name from SQS, ran TruffleHog against it, and logged the results.

    “Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000,” describes Marshall.

    “This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours.”

    The total cost for the entire public GitLab Cloud repositories using the above method was $770.

    The researcher found 17,430 verified live secrets, nearly three times as many as in Bitbucket, and with a 35% higher secret density (secrets per repository), too.

    Historical data shows that most leaked secrets are newer than 2018. However, Marshall also found some very older secrets dating from 2009, which are still valid today.

    Volume of exposed secrets
    Source: Truffle Security

    The largest number of leaked secrets, over 5,200 of them, were Google Cloud Platform (GCP) credentials, followed by MongoDB keys, Telegram bot tokens, and OpenAI keys.

    The researcher also found a little over 400 GitLab keys leaked in the scanned repositories.

    Types of exposed secrets on GitLab
    Source: Truffle Security

    In the spirit of responsible disclosure and because the discovered secrets were associated with 2,804 unique domains, Marshall relied on automation to notify affected parties and used Claude Sonnet 3.7 with web search ability and a Python script to generate emails.

    In the process, the researcher collected multiple bug bounties that amounted to $9,000.

    The researcher reports that many organizations revoked their secrets in response to his notifications. However, an undisclosed number of secrets continue to be exposed on GitLab.


    The 2026 CISO Budget Benchmark

    It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

    Learn how top leaders are turning investment into measurable impact.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleRestarts and freezes disrupt everyday use -gamer Asus TUF Gaming A18 with teething issues
    Next Article Coinbase Bitcoin Premium Turns Positive as Silver Hits Record High
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    ASUS warns of new critical auth bypass flaw in AiCloud routers

    November 28, 2025

    Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

    November 18, 2025

    Government faces questions about why US AWS outage disrupted UK tax office and banking firms

    October 23, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025467 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025159 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202584 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202563 Views
    Don't Miss
    Technology December 3, 2025

    Are We Ready for AI Enshittification? What Happens When the Systems You Trust Suddenly Stop Working

    Are We Ready for AI Enshittification? What Happens When the Systems You Trust Suddenly Stop…

    UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

    Strategic shift pays off as Okta bids to ease agentic AI risk

    Use of digital ID in UK achieves statutory status

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Are We Ready for AI Enshittification? What Happens When the Systems You Trust Suddenly Stop Working

    December 3, 20250 Views

    UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

    December 3, 20250 Views

    Strategic shift pays off as Okta bids to ease agentic AI risk

    December 3, 20250 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.