Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe

July 28, 2025

South Korean beauty products could be subject to steep tariffs

July 28, 2025

What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa

July 28, 2025
Facebook X (Twitter) Instagram
Trending
  • Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe
  • South Korean beauty products could be subject to steep tariffs
  • What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa
  • Trump calls for DC to restore old NFL name as experts say Native mascots cause harm
  • The Founder Of Shake Shack Is Now A Billionaire
  • What to know about the dating app Tea and its hacked data
  • If you don’t have diabetes, do you really need a continuous glucose monitor?
  • Blue Ivy shines on stage during Beyoncé’s Cowboy Carter tour
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Monday, July 28
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Files Deleted From GitHub Repos Leak Valuable Secrets
Cybersecurity

Files Deleted From GitHub Repos Leak Valuable Secrets

adminBy adminApril 23, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 52


Security researcher Sharon Brizinov earned $64,000 in bug bounties after finding hundreds of secrets leaking in dozens of public GitHub repositories.

What makes Brizinov’s findings special is that the leaked secrets were found in files that had been deleted from the scanned repositories, which also reveals risks associated with a lack of appropriate actions when dealing with such leaks.

The issue his research brings to the spotlight is that developers may not be aware that Git retains copies of all files within a repository, even if they are no longer available in the working directory.

A distributed revision control system, Git tracks content using a commit – tree – blob structure. It captures snapshots of the repository’s state, and relies on branches for reviewing commit history, and on tags for referencing specific commits.

Because it stores each version of a file as a unique object and keeps a complete history of the changes made to a repository, Git makes it easy to revert to previous states and to restore files that have been deleted or removed from the working directory and committed.

“Once a commit is created, its data is stored in .git/objects and remains there even if it’s no longer referenced by any branch or tag. Unreferenced (dangling) objects aren’t removed immediately — they’re typically retained for around two weeks before being eligible for garbage collection,” Brizinov explains.

Removing files from Git history may prove difficult, as the system maintains references to them in heads and tags, and older commits still contain files removed in newer ones.

“To completely remove a file from history, one must rewrite history using tools like git filter-branch, git-filter-repo or by manually rebasing and running garbage collector (with prune) to clear unreachable objects,” Brizinov says.

Advertisement. Scroll to continue reading.

When it comes to public repositories, he notes, completely removing committed files is virtually impossible, as they may have been copied or cloned elsewhere.

To shed light on these risks, Brizinov built an automated tool to clone public repositories, traverse all commits to find deleted files, restore them, and scan them for secrets such as API keys, tokens, and credentials.

He focused on companies with active bug bounty programs and those with Github repositories that have over 5,000 stars, and discovered hundreds of active secrets, mainly in binary files that had been deleted after being committed to the repository.

In addition to platform-specific developer tokens and sessions, and email SMTP credentials, Brizinov discovered tokens for GCP projects, AWS, Slack, GitHub, OpenAPI, HuggingFace, and Algolia.

“Why did the secrets get leaked in the first place? After analyzing dozens of real-impact cases, I can summarize this question into three explanations— lack of knowledge of how Git works, not fully realizing what was committed due to binary files or hidden files, and blindly trusting Git rewrite-history tools,” the researcher notes.

He also points out that, if a secret-leaking file is committed, developers should not simply delete it, but also rotate the potentially impacted secrets, to eliminate the risk of compromise.

Related: 39 Million Secrets Leaked on GitHub in 2024

Related: Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack

Related: Hacker Stole Secrets From OpenAI

Related: GitHub Actions Artifacts Leak Tokens and Expose Cloud Services and Repositories



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

The Founder Of Shake Shack Is Now A Billionaire

July 26, 2025

Todd Williamson/Getty Images for Airbnb Danny Meyer made his name opening up a string of…

‘South Park’ Creators Trey Parker and Matt Stone Are Now Billionaires

July 25, 2025

How Jeffrey Epstein Got So Rich

July 25, 2025

Vanta Raises Funds At $4 Billion Valuation—Despite Not Needing Cash

July 23, 2025
Our Picks

Crème fraîche creates a creamy broth in a briny-sweet steamed clams recipe

July 28, 2025

South Korean beauty products could be subject to steep tariffs

July 28, 2025

What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa

July 28, 2025

Trump calls for DC to restore old NFL name as experts say Native mascots cause harm

July 27, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.