#TruffleSecurity
Trufflehog est un outil d'analyse permettant de monitorer et découvrir les secrets et autres credentials qui pourraient fuiter par inadvertance dans vos GutHub, GitLab, S3, ElasticSearch, etc ... ⬇️

github.com/trufflesecur...
GitHub - trufflesecurity/trufflehog: Find, verify, and analyze leaked credentials
Find, verify, and analyze leaked credentials. Contribute to trufflesecurity/trufflehog development by creating an account on GitHub.
github.com
February 19, 2025 at 7:11 AM
📦 trufflesecurity / trufflehog
⭐ 16,075 (+18)
🗒 Go

Find, verify, and analyze leaked credentials
GitHub - trufflesecurity/trufflehog: Find, verify, and analyze leaked credentials
Find, verify, and analyze leaked credentials. Contribute to trufflesecurity/trufflehog development by creating an account on GitHub.
github.com
October 31, 2024 at 10:01 PM
force-push-scanner

Scan for secrets in dangling commits on GitHub using GH Archive data.

https://github.com/trufflesecurity/force-push-scanner
July 11, 2025 at 7:15 AM
📦 trufflesecurity / trufflehog
⭐ 12,311 (+26)
🗒 Go

Find and verify credentials
GitHub - trufflesecurity/trufflehog: Find and verify credentials
Find and verify credentials. Contribute to trufflesecurity/trufflehog development by creating an account on GitHub.
github.com
October 20, 2023 at 6:50 AM
Wild. This scanner looks for force pushes and shit for mistakenly referenced secrets.

https://github.com/trufflesecurity/force-push-scanner

Haven't played with it but ooo.

#scanner #github
GitHub - trufflesecurity/force-push-scanner: Scan for secrets in dangling commits on GitHub using GH Archive data.
Scan for secrets in dangling commits on GitHub using GH Archive data. - trufflesecurity/force-push-scanner
github.com
July 12, 2025 at 3:57 AM
Found a nice tool called TruffleHog that can search for secrets that might be accidentally leaked in files, logs, etc.
github.com/trufflesecur...
GitHub - trufflesecurity/trufflehog: Find, verify, and analyze leaked credentials
Find, verify, and analyze leaked credentials. Contribute to trufflesecurity/trufflehog development by creating an account on GitHub.
github.com
October 23, 2025 at 5:32 PM
September 6, 2026 at 7:44 AM
So...I want to put this in the training docs. For security purposes.
trufflesecurity on TikTok
Phishing training is awful #appsec #phishing #security #cybersecurity
www.tiktok.com
May 4, 2023 at 7:31 PM
Thank you to @trufflesecurity for supporting #OWASP Global AppSec San Francisco as a silver exhibitor. We are looking forward to having you join us. sf.globalappsec.org/ #developer #appsec #cybersecurity #ai
September 22, 2024 at 8:00 PM
Thank you to @trufflesecurity for supporting #OWASP Global AppSec San Francisco as a silver exhibitor. We are looking forward to having you join us. sf.globalappsec.org/ #developer #appsec #potatosecurity #ai
September 22, 2024 at 8:13 PM
More than 9,000 publicly exposed AWS access keys remain active, posing potential risks to hundreds of companies, according to Truffle Security.

Read Full Article: deccanfounders.com/2026/24/news...

#deccanfounders #aws #amazon #trufflesecurity #IAMusers #keyexposure
August 24, 2026 at 11:02 AM
Truffle Security finds 9,300 leaked AWS access keys still active after years, with 768 giving full administrative control over corporate cloud accounts

#Aws #CloudSecurity #CredentialExposure #Cybersecurity #DataLeak #HuggingFace #TruffleSecurity
768 Leaked AWS Keys Expose Corporate Cloud Admin Access
Truffle Security finds 9,300 leaked AWS access keys still active after years, with 768 giving full administrative control over corporate cloud accounts
pulseofnations.lol
August 24, 2026 at 12:20 AM
Researchers found 768 still-active AWS access keys with root or admin privileges exposed in public code repositories and AI training datasets.

#Aws #CloudSecurity #Cybersecurity #DataExposure #LeakedKeys #TruffleSecurity
768 Exposed AWS Keys Grant Full Admin Access
Researchers found 768 still-active AWS access keys with root or admin privileges exposed in public code repositories and AI training datasets.
pulseofnations.lol
August 22, 2026 at 7:10 PM
Over 9,300 exposed AWS access keys remain active, including 817 tied to companies, 526 root keys, and 242 AdministratorAccess users. Leaks could enable account takeover and data theft. #AWS #HuggingFace #TruffleSecurity
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 AWS access keys exposed over a four-year period are still active, with hundreds tied to companies, root accounts, and AdministratorAccess users. Truffle Security warns that some of these leaked credentials could give attackers full control of AWS environments, including data theft, account takeover, and cryptomining, with Hugging Face being the largest source of exposed keys. #AWS #HuggingFace #TruffleSecurity
www.hendryadrian.com
August 22, 2026 at 1:30 AM
trufflehog 3.95.3: breaking changes
AnalysisInfo to SecretParts rename requires detector result updates in CI pipelines.
Upgrade carefully.

→ releaseport.com/r/trufflesecurity-trufflehog/v3-95-3
trufflehog v3.95.3
SecretParts rename
releaseport.com
May 12, 2026 at 11:05 AM
May 13, 2026 at 11:40 AM
February 7, 2026 at 10:09 AM
September 6, 2025 at 6:16 PM
trufflesecurity/trufflehog
Check out trufflesecurity/trufflehog on GitHub
github.com
January 27, 2025 at 6:51 AM
The security gap was discovered by Trufflesecurity researchers and reported to Google last year on September 30. www.bleepingcomputer.com/news/securit...
Google OAuth flaw lets attackers gain access to abandoned accounts
A weakness in Google's OAuth "Sign in with Google" feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various softw...
www.bleepingcomputer.com
January 15, 2025 at 1:01 PM