Research Finds Nearly 800,000 Access Keys Exposed Online

  /     /     /  
Publicated : 23/11/2024   Category : security


Research Finds Nearly 800,000 Access Keys Exposed Online


The keys were primarily for access to databases and cloud services.



When AWS keys were exposed in GitHub repositories, GitHub responded by invalidating those keys. Researchers at Digital Shadows have found that this proper action doesnt end the issue of exposed keys as they have found almost 800,000 keys available on the Web.
The researchers searched approximately 150 million entities across GitHub, GitLab, and Pastebin during a 30-day period in August and September to find the roughly 800,000 keys. They discovered that more than 40% of the keys were database keys while 38% were for cloud services. Redis was the most common database involved, while Google Cloud API was the most common cloud service key.
In their blog post on the research, Digital Shadows notes three services — Trufflehog, GitRob, and GitHub Secret Scanning — that can help organizations search for their own keys that might have been exposed online.
For more, read
here
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Research Finds Nearly 800,000 Access Keys Exposed Online