Categories: Cyber Security News

65% of Leading AI Companies Expose Verified Secrets and Access Keys on GitHub

A security investigation has uncovered a concerning trend: nearly two-thirds of the world’s most prominent AI companies have accidentally leaked sensitive credentials on GitHub.

These exposures include API keys, authentication tokens, and other critical secrets that could give attackers direct access to their systems.

Researchers studied 50 leading AI companies from the Forbes AI 50 list and found that 65% had exposed verified secrets.

These companies are worth over $400 billion combined, making this security gap particularly serious.

The leaked credentials weren’t just sitting in active repositories; many were hidden in deleted forks, old code branches, and personal developer accounts.

How Secrets End Up Exposed

Modern secret leaks operate like an iceberg. The obvious risks include credentials accidentally committed to public repositories.

But deeper problems exist beneath the surface. Deleted repository forks keep their complete commit history, making old secrets permanently accessible to anyone who finds them.

Automated workflow logs often contain deployment credentials, and developer personal accounts frequently harbor organizational secrets that were committed and forgotten.

This layered exposure creates multiple attack vectors that standard scanning tools miss entirely.

The exposed credentials grant access to some of AI companies‘ most valuable assets. Leaked WeightsAndBiases tokens exposed training data for private machine learning models.

Findings and Analysis

HuggingFace authentication tokens provided access to thousands of private model repositories.

ElevenLabs API keys and LangChain credentials gave attackers gateway access to proprietary systems and sensitive information.

Beyond immediate technical risks, these leaks revealed organizational structures, team member lists, and internal relationships, valuable information for social engineering attacks.

The research revealed an important fact: one AI company maintained 60 public repositories with 28 organization members and had zero exposed secrets.

This proves that solid secrets management genuinely works.

Companies like LangChain and ElevenLabs quickly acknowledged and fixed disclosed vulnerabilities.

However, nearly half of the reported leaks either failed to reach their targets or received no response. Many startups lack official security disclosure channels.

AI organizations need three immediate actions: deploy mandatory secret scanning across all public code repositories, establish proper security disclosure channels from the beginning, and work with the security community to ensure detection tools support emerging secret formats.

The AI revolution depends on innovation and speed, but that future becomes worthless if the innovations themselves become compromised. For every AI company, securing secrets must keep pace with its advancing capabilities.

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Updates

The post 65% of Leading AI Companies Expose Verified Secrets and Access Keys on GitHub appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Forza Horizon 6 Suffers Disastrous Leak as Steam Preload Files Are Made Available Without Encryption

Forza Horizon 6 suffered a significant leak after the entire game was reportedly made available…

2 seconds ago

Jodi’s Journal: The rest of the story behind Forward Sioux Falls

May 10, 2026 Imagine if the biggest, most influential businesses in this country came together…

50 minutes ago

Crimson Desert Adds Surprise Claw Machine Mini-Game and Lets Pet Dogs Attack Enemies as Part of Update 1.06.00

Crimson Desert developer Pearl Abyss has released this week’s update as promised, and it adds…

56 minutes ago

Nearly 50 Years Later, WKRP in Cincinnati Becomes a Real Radio Station

It took nearly 50 years. WKRP in Cincinnati is no longer just a TV sitcom.…

1 hour ago

Record turnout, beautiful weather highlight Friday’s Chamber Golf Tournament at Big Creek

The Mountain Home Area Chamber of Commerce hosted its 2026 Four-Person Scramble Golf Tournament Friday…

1 hour ago

Lead Hill man competes on Netflix reality show “Million Dollar Secret”

Growing up and spending all of his 44-years in Lead Hill and living on the…

1 hour ago

This website uses cookies.