trufflesec.bsky.social @trufflesec.bsky.social · 17/09/2025⚠️ Supply chain attacks keep stacking up- Salesforce, S1ngularity/NX & more. ⚒️ The same tools attackers use to find secrets are the ones defenders need too. 🐷 That’s why threat intel groups recommend TruffleHog. 🔗 Learn why it shows up in your logs: trufflesecurity.com/blog/truffle... 100
trufflesec.bsky.social @trufflesec.bsky.social · 18/07/2025🔐 8,437 #GCP images. 147M files. 0 live secrets. ☁️ GCP’s strict image controls show clear results vs. AWS & Azure. 🔗 Full CloudQuarry report: trufflesecurity.com/blog/guest-p... 000
trufflesec.bsky.social @trufflesec.bsky.social · 01/07/2025 🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub. 🔗A guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-p... 010
trufflesec.bsky.social @trufflesec.bsky.social · 13/03/2025🔥 You can now add TruffleHog to Burp Suite! 🌐 Install it directly from the BApp Store 🔍Scan web traffic for live, verified credentials—active & exploitable Because secrets don’t just leak in code… 😬 🔗 trufflesecurity.com/blog/introdu... 032
trufflesec.bsky.social @trufflesec.bsky.social · 27/02/2025 We scanned 400TB of DeepSeek’s training data & found: 🚨 ~12K live API keys & passwords 🌐 2.76M affected pages 🔄 One key appeared 57K+ times 🔑 219 secret types (AWS root keys, Slack webhooks, etc.) 🔗 Full research: trufflesecurity.com/blog/researc... 000
trufflesec.bsky.social @trufflesec.bsky.social · 21/02/2025Removing Jeff Bezos from my bed - Do you expect to find an AWS key in your bed? We found one, and we removed it. We’re sleeping great now. 🔗 trufflesecurity.com/blog/removing-jeff-bezos-from-my-bed 022
trufflesec.bsky.social @trufflesec.bsky.social · 24/01/2025🐷 Under the Hood of TruffleHog! ⚡ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. 🚀 👉 trufflesecurity.com/blog/under-t... 031
trufflesec.bsky.social @trufflesec.bsky.social · 13/01/2025🚨Today we are announcing a new OAuth bug that affects millions of accounts 🌟 TLDR: Google’s OAuth login doesn’t protect against someone purchasing a failed startup’s domain and using it to re-create email accounts for former employees 👉 full blog: trufflesecurity.com/blog/million... 052
trufflesec.bsky.social @trufflesec.bsky.social · 08/01/2025Vigilante Justice on GitHub. 🦇🦸 Here's how to spray painting on other fraudster's GitHub Activity Graph. trufflesecurity.com/blog/vigilan... 021
trufflesec.bsky.social @trufflesec.bsky.social · 19/12/2024🚨 10% of SaaS platforms mishandle GitHub OAuth tokens, opening potential backdoors into corporate accounts. 😱 ⚠️ Extends to Azure, Slack & more—increasing risk with poor token handling. 🛑 The issue isn’t OAuth; it’s how platforms secure tokens. 👉 trufflesecurity.com/blog/mishand... 012
trufflesec.bsky.social @trufflesec.bsky.social · 09/12/2024🐷 TruffleHog now decodes APKs to scan for secrets 🚀 💡 Why it matters: 🔍 APKs often leak secrets, but scanning was slow & complex. 🔓 Now it’s fast, efficient & scalable. 📊 Tested on WhatsApp & Facebook Messenger—up to 16.5x faster! 👉https://trufflesecurity.com/blog/cracking-open-apk-files-at-scale 020