GitHub’s default push protection still left hundreds of thousands of working logins in public view.

SecurityWeek reports roughly 500,000 active credentials sitting in GitHub repositories, and about 200,000 of those landed after the platform turned push protections on by default. If your cybersecurity program treats a green secret scanning checkbox as containment, you are briefing a vendor setting. The password still works.

Your firewall never inspects a git push.

That is the operational story this week, and it is bigger than one platform’s scanner. Developers keep shipping live secrets into public history. Carmaker apps ship VINs, emails, phones, and location to advertising and analytics firms as a product feature. Crews tied to ATM malware convert stolen access into cash, then try to launder it. The common failure is identity leaving through a channel you already trust.

Login prompt representing credentials exposed in public code repositories
Live logins in public Git history still authenticate long after a scanner checkbox turns green.

Public Repos Still Hand Out Live Access

Push protection is a speed bump on a new commit. It does not rewind what already shipped, and it does not revoke the token sitting in a gist from last year. SecurityWeek’s count of still-active credentials is the part you should take personally. Dead secrets are hygiene theater. Live ones are access.

This is a bad look for any team that briefed “we enabled push protection” as the close of a risk ticket. The real problem here is leftover validity. You can paste the secret and get in.

Attackers do not need a novel brute-force campaign against an account whose password is already in a public blob. They paste, they log in, they look like a developer. Your threat-protection stack at the edge sees a successful authentication. Threat detection that keys on failed logins will stay quiet.

Treat every hit on a public secret as an incident. Incident response for a leaked cloud key is the same job as a compromised workstation: revoke, rotate, review audit logs for the window the secret was valid, then check whether a second key was minted from the first.

If the secret is an admin API token, assume the holder already enumerated. Do not wait for a vendor to mail you a takedown.

You own the clock.

Approved Channels Move the Same Identifiers

Northeastern University researchers, working with Consumer Reports, tested 21 vehicles and 30 carmaker apps. Some of those apps sent vehicle identification numbers, email addresses, phone numbers, or location data to advertising, tracking, and analytics companies. The app did what the vendor shipped.

Connected car dashboard representing OEM apps sending owner data to third parties
Fleet and consumer car apps can hand VINs, emails, and location to ad and analytics firms without a break-in.

That is the same class of failure as a live GitHub secret. Data left through a supported path. Your cyber security review of the vendor likely stopped at the privacy policy PDF and a SOC 2 logo. Defense in depth that ends at the corporate firewall never sees a mobile SDK talking to an ad network from an employee’s phone in the parking lot.

If you issue cars, badges, or BYOD stipends, those companion apps sit next to your IdP in the identity picture. VIN plus email plus last GPS ping is enough to stalk a staffer or clone a service record. Ask the vendor where telemetry goes, and demand a written list of third parties. If they cannot produce it, you already have your answer.

Treasury’s OFAC action against Venezuelan nationals and companies tied to an ATM jackpotting scheme linked to Tren de Aragua is the cash end of that chain. Malware on a machine is how you empty a cassette. Valid credentials in a repo are how you empty a cloud account. Sanctions hit the money handlers after the theft. Your job is to make the first hop expensive.

ATM targeted in a jackpotting scheme that turns stolen access into cash
Jackpotting crews cash out machine access. Cloud thieves cash out the keys you left in Git.

Cybersecurity Work Starts With Secret Retirement

Stop arguing about scanner brands. Prove that secrets cannot survive a push, a merge, or a six-month-old branch. Security hardening here is boring on purpose.

Do this this week.

  • Inventory every public and internal Git host your org can push to, including forgotten GitLab, Gitea, and personal mirrors that clone corporate code.
  • Search for high-value patterns: cloud keys, VPN PSKs, database URLs with passwords, CI tokens, and service-account JSON.
  • Revoke first, then rotate. A rotated secret that still has the old one valid is two incidents.
  • Pull auth logs for those identities covering the entire exposure window, not just the last 24 hours.
  • Disable unused personal access tokens and require short TTL plus hardware-backed SSO for anything that can mint new secrets.

Keep the hunt on a calendar. Public Git is a living index. A contractor’s fork from last spring can still carry a production key. Run a quarterly sweep of org names, vanity domains, and former employee handles. Block the commit in CI, and still scan history, because history is where the live ones hide.

Put companion apps and fleet telematics on the same vendor register as your IdP. If an OEM cannot name every analytics endpoint, treat that as an unapproved data processor. Strip location and VIN from anything that does not need it for the repair. Staff should be able to use a vehicle without donating a movement graph to an ad exchange.

For anything that can become cash, including privileged cloud keys and payment-adjacent hosts, require step-up auth and egress allowlists. Watch for new API keys minted by identities that already look legitimate. That pattern shows up in jackpotting crews and in cloud theft alike.

A revoked secret, a closed public repo, and a log that proves the old key went unused: that is a control you can brief to a board.

Rotate the key before you admire the scanner.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.