NEW RESEARCH
๐ Between August 2022 and August 2026๐จ
๐ฅ Over 700 Leaked Corporate AWS Keys Held Full Admin Rights.
๐ตOnly 9.5% had billing alarms; million dollar bills waiting to happen.
๐ง We're launching TruffleHog AWS Analyze to help.
๐
https://t.co/PwXM6ku6Q8
NEW RESEARCH
๐ Between August 2022 and August 2026๐จ
๐ฅ Over 700 Leaked Corporate AWS Keys Held Full Admin Rights.
๐ตOnly 9.5% had billing alarms; million dollar bills waiting to happen.
๐ง We're launching TruffleHog AWS Analyze to help.
๐
https://t.co/PwXM6ku6Q8
AI #agents don't just need permissions. In a recent @Inc Magazine article, @TruffleSec CEO Dylan Ayrey made the case that AI agents need the same security scrutiny we give human users, if not more. As AI evolves, so does the need for agent #security.
Read the full article below:
Our CEO @InsecureNature on the rogue agent incidents at OpenAI, Anthropic and Meta: the bar for hacking used to be subject matter expertise, and now the models have it.
๐จ Your AI-generated images may be leaking more than you think
โ ๏ธ Every ComfyUI image embeds prompts, file paths, API keys & GPS data - even from nodes that never ran
๐ 2.49M Discord images scanned: 159,752 leaked metadata, 681 had live API keys
๐https://t.co/VC5cDjhbiX
๐จTruffleHog Enterprise is now on the Slack Marketplace!
๐Scan every message, channel & DM for leaked secrets: historical + continuous
Also: ๐ Activity Log for scan visibility + ๐๏ธ Source Archiving to retire integrations without losing findings.
๐ https://t.co/mVFUlby3vI
We scanned HuggingFace. ๐๐๐
This was the largest secret scan of AI training data ever: 7.6 PB. ๐๐๐๐๐๐๐๐๐
๐Found 221,303 live unique credentials in 6,003 public datasets
โ๏ธCloud keys, live DBs, API keys worth ~$920K/yr.
โ ๏ธTraining data has no undo: one key hit 1,131 datasets
๐ https://t.co/H3Njla3uSB
๐จ New research: a cache flaw in https://t.co/KPgPxxs3KO leaked freshly minted API keys to other users
๐gzip responses to an authenticated API key request got cached at the Fastly edge, then served to the next user, no auth needed
โ Now fully fixed
๐ https://t.co/lBBw6VcxfE
๐จ New research: how we helped prevent a supply chain attack
๐ณA live #Docker Hub token sat in a public GitLab CI artifact with write access to all 384 Torizon images (4.5M+ pulls) ๐ฆ
โ ๏ธ #GitLab masks secrets in logs, but NOT artifacts.
๐ https://t.co/6xsDORLscv
๐ New in TruffleHog Enterprise!
๐บ๏ธ Topology: see the blast radius of a leaked secret, not just where it leaked
๐ Shared Secrets: secure, expiring links to get findings to the right person
๐ Multi-org GitHub scanning from one connection
๐https://t.co/s8cSPLJ6IV
๐จ Google is fixing a Gemini API key privilege escalation we disclosed.
~3,000 public API keys silently gained Gemini access, with bills up to $1M ๐ธ๐คฏ
๐ New auth keys are rolling out before Sept. 2026 -now's the time to audit your credentials.
๐https://t.co/BkJaritJ7s
๐ Your PR scanner caught it. But PR scanning alone has 3 blind spots:
โฑ๏ธ Timing gap: pushes go live BEFORE the PR opens
๐ฟ Abandoned branches: never scanned
๐ "Fixed" โ revoked
Secrets are exploited within seconds. One gate isn't enough.
๐https://t.co/P6b6ULnlco
๐จ A "deleted" PyPI package exposed an admin GitHub PAT - granting access to Apache & Astronomer for 2.5 years
๐ 678K โdeletedโ packages were recovered from object storage & 190 live secrets found
โ Deletion โ revocation ๐ Rotate your creds!
๐https://t.co/1eKvqDVKCp
๐ CISA admin GitHub App key still LIVE 2 days after Krebs reported it.
And there was more:
๐ Org-wide GitHub admin access
๐ฆ 6 JFrog tokens + master keys
๐ Guessable DB passwords
๐https://t.co/8sF2aMEbfk
๐ท The May release of TruffleHog Enterprise is out.
๐ New summary dashboard. See your secrets program at a glance.
๐ TruffleHog GCP Analyze just got smarter. IAM insights + guided rotation.
๐https://t.co/2RUiiAOxnX