Data Protection

39 Million Secrets Leaked on GitHub in 2024

GitHub has announced new capabilities to help organizations and developers keep secrets in their code protected.

GitHub vulnerability

Keeping secrets protected on GitHub is now easier, courtesy of new capabilities that the Microsoft-owned code hosting platform announced on Wednesday.

With GitHub discovering roughly 39 million leaked secrets across the platform in 2024, it’s clear that inadvertently exposing secrets in code happens rather often, and threat actors are known to harvest and exploit them within minutes.

To help organizations and developers better protect tokens, credentials, and other secrets and prevent their exposure, GitHub is now offering Secret Protection and Code Security as standalone products for enterprise customers.

According to GitHub, the two capabilities should now be within the reach of more organizations, as many did not previously afford the suite of tools the two were bundled within. Secret Protection is free for public repositories.

Additionally, the platform has made its standalone security products available as add-ons for GitHub Team organizations, meaning smaller development teams no longer need to upgrade to GitHub Enterprise to use them.

To further help organizations identify and neutralize code secrets before they are leaked, GitHub also allows organizations across GitHub Team and Enterprise plans to run a secret risk assessment across all their public, private, and internal repositories.

Advertisement. Scroll to continue reading.

“The point-in-time scan provides clear insights into the exposure of your secrets across your organization, along with actionable steps to strengthen your security and protect your code. In order to lower barriers for organizations to use and benefit from the feature, no specific secrets are stored or shared,” GitHub notes.

The capability has been released in public preview and the code-hosting platform is requesting feedback on how it could improve it.

GitHub also notes that organizations can use its push protection feature to block secrets from accidental exposure, and recommends that they implement strong secrets management capabilities to ensure increased security.

Related: GitHub Launches Fund to Improve Open Source Project Security

Related: GitHub Patches Critical Vulnerability in Enterprise Server

Related: GitHub Makes Copilot Autofix Generally Available

Related: Git Vulnerabilities Led to Credentials Exposure

Related Content

Application Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.

Artificial Intelligence

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

Malware & Threats

Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.

Malware & Threats

A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware.

Artificial Intelligence

Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.

Supply Chain Security

By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.

Vulnerabilities

A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance.

Application Security

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version