
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found.
Summary
GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated successfully against GitHub’s API. Those keys represented 440 distinct GitHub […] The article Leaked GitHub app keys retain live access appeared first on Arabian Post .
This is a brief wire summary — the full story (linked below) has the complete details.
KazaSec's take
Web and API vulnerabilities like this are exactly what manual penetration testing is designed to catch — automated scanners routinely miss the logic flaws and chained issues that cause the most damage in practice.
Coverage details
We've archived 149 other articles touching the same topic (cybersecurity) — see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.