Skip to content

Secure Your Digital Life

  • Home
  • Data Protection
  • Home
  • Data Protection
  • GitHub secrets: Deleted files still pose risks
Data Protection

GitHub secrets: Deleted files still pose risks

“I built an automation that cloned and scanned tens of thousands of public GitHub repos for leaked secrets,” Brizinov said in a blog post. “For each repository, I restored deleted files, found dangling blobs, and unpacked .pack files to search in them for exposed (secrets).”

Brizinov made $64,000 in bug bounty winnings for finding dozens of repositories belonging to Fortune 500 companies leaking over hundreds of secrets this way.

Git history retains files even after deletion

According to the discovery, Git retains a complete history of changes, meaning that deleted files and their contents can still be accessed unless properly purged.  “Developers often forget that Git history retains everything, even after files are removed from the working directory,” Brizinov noted.

Related Posts

Data Protection

Fake AI video generators drop new Noodlophile infostealer malware

Data Protection

Microsoft Teams will soon block screen capture during meetings

Post navigation

Previous: Linux ‘io_uring’ security blindspot allows stealthy rootkit attacks
Next: Darcula Adds GenAI to Phishing Toolkit, Lowering the Barrier for Cybercriminals
  • Fake AI video generators drop new Noodlophile infostealer malware
  • Microsoft Teams will soon block screen capture during meetings
  • What Is CaaS (Containers-as-a-Service)?
  • Where To Watch Why Women Kill for Free (Seasons 1 & 2) in 2025
  • Your Android phone is getting a new security secret weapon – and it’s a big deal
All Rights Reserved 2026.
Proudly powered by WordPress | Theme: Fairy by Candid Themes.