Urgent.News

What's breaking now, across thousands of outlets.

Tech

Leaked GitHub app keys retain live access

Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found. GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated…

Security researchers have discovered that hundreds of private GitHub App keys, used for authentication and access control, remain active despite being publicly exposed. GitGuardian analyzed over 500,000 leaked keys and found that 474, or roughly 10%, successfully authenticated against GitHub’s API, representing 440 distinct GitHub Apps.

The compromised keys granted various levels of access, including repository content manipulation, self-hosted runner administration, and organization-wide control. GitHub's own documentation advises manual revocation of these keys, but many remain usable until explicitly removed. The issue spans from internal tools to applications used by major organizations like the CDC, underscoring the importance of rotating and securely storing private keys.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

JavaScript Array Methods: 7 Essential Methods Every Developer Needs

The Array object in JavaScript enables us to store a collection of data under a single variable name and provides various built-in methods to manipulate that data.

  • Array forEach iterates array elements, performing actions without returning a value.
  • Array map creates new array by applying function to each element, preserving original.
  • Array filter generates new array with elements passing test function, leaving original unchanged.

Cross-Chain Bridge Risk Assessment: Gauntlet

Cross-Chain Bridge Risk Assessment: Gauntlet Target Protocol : Gauntlet (TVL: $1630.6M) Cross‑Chain Bridge Risk Assessment – Gauntlet TVL: ≈ $1.63 B (Ethereum + L2s) Date: 24 Sep 2026 Prepared by…

  • Gauntlet bridge moved $1.63B between Ethereum and Layer-2 networks
  • Three high-severity smart contract vulnerabilities found
  • Risk score of 7.4/10 indicates moderate-to-high systemic risk

More from Thursday 24 September →