pwshub.com

Hackers love GitHub dorks - SecOps love outsmarting them

Partner Content In an era where code is the backbone of modern businesses, GitHub is quickly becoming the biggest attack surface of all.

GitHub is growing at a 22 percent rate year-over-year, with about 20 million new accounts and 50 million new code repositories created annually. This growth brings an explosion of hard-coded secrets. GitGuardian, which specializes in secrets detection and remediation, detected 12.8 million new secrets exposed this way last year alone, a number that has risen by a factor of four over the past four years

No wonder GitHub has become a playground for malicious actors looking for easy catches floating in this vast ocean of source code, aka dorks.

This new reality underscores a need for companies to track and manage their GitHub footprint. To help threat intel and security analysts get a comprehensive overview of their organization's posture, GitGuardian is offering a free, one-click, security audit.

GitGuardian's GitHub Security Audit tool is designed to give you an instant, in-depth analysis of your organization's domain GitHub footprint. Here are the features that make it an interesting addition to your security toolkit:

- Comprehensive developer footprint analysis: Discover not just your official GitHub organization members, but all developers using company emails across GitHub.

- Attack surface quantification: Get a clear picture of your public GitHub exposure.

- Historical leak assessment: Uncover how many of your developers' secrets have been leaked in the past three years.

- Immediate risk identification: Learn which leaks are still valid and pose current security threats.

At the heart of the audit is the Public GitHub Attack Surface Score, which ranges from A to E. It provides an at-a-glance assessment of your overall GitHub security posture. It's a powerful tool for technical teams and executive stakeholders to understand and communicate risk levels.

Once you have a bird's eye view of your current posture, you can do a deep-dive into the metrics with the complimentary in-depth audit report to get actionable insights, including:

- Categorized secret analysis: Break down leaks by type (eg, private keys, cloud provider credentials).

- Direct company mentions: Identify commits explicitly referencing your company in code.

- Developer risk profiling: Pinpoint which developers have been involved in leaks.

- Sensitive file detection: Spot secrets published within inherently sensitive files.

- Public repository event tracking: Be alerted when private repos go public, potentially exposing historical sensitive data.

- Zombie leak identification: Uncover secrets that, while erased from GitHub, persist in archives.

This audit tool is powered by GitGuardian's secrets detection engine, which has been operational since 2017, analyzing billions of commits coming from GitHub. The algorithms and detectors are constantly trained on a dataset of four billion commits, offering significant precision and recall.

Don't let your company's secrets become another statistic. Take advantage of GitGuardian's free GitHub Security Audit to start building a more secure GitHub presence and protect your organization's crown jewels.

You can check if your organization is exposed on GitHub now and start your free GitHub security audit by clicking here.

Contributed by GitGuardian.

Source: theregister.com

Related stories
1 month ago - Windscribe allows you to hide your IP address and encrypt your online activity, ensuring private browsing while also giving access to blocked content. It's a good free VPN to have handy if you need it casually. It supports Windows, macOS,...
1 month ago - Technological advancements with baby monitors, which have varying levels of security, have brought new risks, including potential hacking.
1 month ago - Cybersecurity researchers found new Iranian hacker networks targeting U.S. political campaigns. Kurt “CyberGuy" Knutsson reveals what you need to know and how to protect yourself.
1 month ago - A hacker shared 240 gigabytes of Toyota customer information on a dark web forum that included contact and financial information, emails and other data.
1 month ago - There's a new method hackers are using to exploit Windows devices, which can expose numerous old vulnerabilities to allow them to take full control of your system.
Other stories
2 minutes ago - Score huge savings on Fire tablets, Echo speakers, Fire TV Sticks, Ring video doorbells and more.
2 minutes ago - If you're not storing unique passwords for all of your websites and services in a secure place, Apple's Passwords app gives you an incentive to start now.
2 minutes ago - Using expired makeup can lead to serious eye and skin problems. Here's when to toss it and why it matters for your health.
2 minutes ago - The next Call of Duty game is here, and subscribers can play it now at no additional charge.
3 minutes ago - Upgrade your home with a new smart garage door. Our CNET experts have tested and selected the top models available.