β οΈ Supply chain attacks keep stacking up- Salesforce, S1ngularity/NX & more.
βοΈ The same tools attackers use to find secrets are the ones defenders need too.
π· Thatβs why threat intel groups recommend TruffleHog.
π Learn why it shows up in your logs: trufflesecurity.com/blog/truffle...
17.09.2025 20:13 β
π 0
π 0
π¬ 1
π 0
π 8,437 #GCP images. 147M files. 0 live secrets.
βοΈ GCPβs strict image controls show clear results vs. AWS & Azure.
π Full CloudQuarry report: trufflesecurity.com/blog/guest-p...
18.07.2025 18:31 β
π 0
π 0
π¬ 0
π 0
πAccessing 15 million "Permanently deleted" commits at scale across GitHub.
πA guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-p...
01.07.2025 20:45 β
π 1
π 0
π¬ 0
π 0
π₯ You can now add TruffleHog to Burp Suite!
π Install it directly from the BApp Store
πScan web traffic for live, verified credentialsβactive & exploitable
Because secrets donβt just leak in codeβ¦ π¬
π trufflesecurity.com/blog/introdu...
13.03.2025 16:57 β
π 4
π 2
π¬ 0
π 0
We scanned 400TB of DeepSeekβs training data & found:
π¨ ~12K live API keys & passwords
π 2.76M affected pages
π One key appeared 57K+ times
π 219 secret types (AWS root keys, Slack webhooks, etc.)
π Full research: trufflesecurity.com/blog/researc...
27.02.2025 17:57 β
π 0
π 0
π¬ 0
π 0
Removing Jeff Bezos from my bed -
Do you expect to find an AWS key in your bed?
We found one, and we removed it. Weβre sleeping great now.
π trufflesecurity.com/blog/removing-jeff-bezos-from-my-bed
21.02.2025 16:04 β
π 2
π 2
π¬ 0
π 3
π· Under the Hood of TruffleHog!
β‘ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. π
π trufflesecurity.com/blog/under-t...
24.01.2025 20:04 β
π 3
π 1
π¬ 0
π 0
π¨Today we are announcing a new OAuth bug that affects millions of accounts
π TLDR: Googleβs OAuth login doesnβt protect against someone purchasing a failed startupβs domain and using it to re-create email accounts for former employees
π full blog: trufflesecurity.com/blog/million...
13.01.2025 22:59 β
π 5
π 2
π¬ 0
π 2
Vigilante Justice on GitHub. π¦π¦Έ
Here's how to spray painting on other fraudster's GitHub Activity Graph.
trufflesecurity.com/blog/vigilan...
08.01.2025 08:02 β
π 2
π 1
π¬ 0
π 0
π¨ 10% of SaaS platforms mishandle GitHub OAuth tokens, opening potential backdoors into corporate accounts. π±
β οΈ Extends to Azure, Slack & moreβincreasing risk with poor token handling.
π The issue isnβt OAuth; itβs how platforms secure tokens.
π trufflesecurity.com/blog/mishand...
19.12.2024 21:57 β
π 1
π 2
π¬ 0
π 0
π· TruffleHog now decodes APKs to scan for secrets π
π‘ Why it matters:
π APKs often leak secrets, but scanning was slow & complex.
π Now itβs fast, efficient & scalable.
π Tested on WhatsApp & Facebook Messengerβup to 16.5x faster!
πhttps://trufflesecurity.com/blog/cracking-open-apk-files-at-scale
09.12.2024 17:33 β
π 2
π 0
π¬ 0
π 1