Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Many Forbes AI 50 Companies Leak Secrets on GitHub

Wiz found the secrets and warned that they can expose training data, organizational structures, and private models.

Development software vulnerability

Cloud security giant Wiz has analyzed GitHub repositories pertaining to the world’s largest AI companies and found that many had leaked verified secrets that could expose sensitive information. 

Leaked secrets are often discovered by GitHub’s own scanners, scans conducted by the repository owners, and automated scans performed by third parties for marketing purposes. 

The cloud security firm wanted to take a different approach in its secrets sprawl study and performed deeper scans that targeted full commit history, commit history on forks, deleted forks, workflow logs, and gists. 

Wiz’s scans also covered members and contributors of the core organization that could inadvertently expose company secrets in their own public repositories. In addition, the scans targeted less common AI-related secrets that may be missed by traditional scanners.

Wiz’s analysis, focusing on the AI companies in the Forbes AI 50 list, showed that 65% of the firms with a GitHub footprint had leaked secrets. “In total, the companies with verified secret leaks are valued at over $400B,” Wiz noted.

The types of leaked secrets included API keys, tokens, and credentials, including ones associated with Google API, Weights & Biases, Flickr, Infura, ElevenLabs, and Hugging Face.

Advertisement. Scroll to continue reading.

Some of the leaked secrets could have exposed private models, training data, and organizational structures.

The impacted AI companies were notified. Firms such as ElevenLabs and Langchain were applauded for their fast response. However, Wiz said nearly half of its disclosures did not reach the vendor or received no response. 

“Many companies lacked an official disclosure channel, failed to reply, and/or failed to resolve the issue,” Wiz said.

The security firm also highlighted some interesting findings. One company that did not have any public repositories and roughly a dozen organization members had been leaking secrets. On the other hand, a company with 60 public repositories and 28 organization members had no exposed secrets, which Wiz believes is indicative of effective secrets management.

Wiz has advised AI companies — the recommendations apply to other types of organizations as well — to prevent secrets sprawl by mandating public VCS secret scanning, establishing disclosure channels to make it easier for third parties to report secret leaks, and prioritizing detection for proprietary secret types.

Related: Truffle Security Raises $25 Million for Secret Scanning Engine

Related: GitHub Workflows Attack Affects Hundreds of Repos, Thousands of Secrets

Related: Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.