<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>The company behind TruffleHog, the popular open-source security project.&#xA;&#xA;YoutTube: https://www.youtube.com/c/TruffleSecurity&#xA;LinkedIn: https://www.linkedin.com/company/trufflesecurity/&#xA;TikTok: https://www.tiktok.com/@trufflesecurity</description><link>https://bsky.app/profile/trufflesec.bsky.social</link><title>@trufflesec.bsky.social - </title><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lz2nk4gzjk24</link><description>⚠️ Supply chain attacks keep stacking up- Salesforce, S1ngularity/NX &amp; more.&#xA;&#xA;⚒️  The same tools attackers use to find secrets are the ones defenders need too.&#xA;&#xA;🐷 That’s why threat intel groups recommend TruffleHog.&#xA;🔗 Learn why it shows up in your logs: https://trufflesecurity.com/blog/trufflehog-in-your-log</description><pubDate>17 Sep 2025 20:13 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lz2nk4gzjk24</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lub3eat2pc2j</link><description>🔐 8,437 #GCP images. 147M files. 0 live secrets.&#xA;&#xA;☁️ GCP’s strict image controls show clear results vs. AWS &amp; Azure.&#xA;&#xA;🔗 Full CloudQuarry report:  https://trufflesecurity.com/blog/guest-post-gcp-cloudquarry-searching-for-secrets-in-public-gcp-images</description><pubDate>18 Jul 2025 18:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lub3eat2pc2j</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lswkwzodmk25</link><description> 🔍Accessing 15 million &#34;Permanently deleted&#34; commits at scale across GitHub. &#xA;&#xA;🔗A guest post by Sharon Brizinov: https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets</description><pubDate>01 Jul 2025 20:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lswkwzodmk25</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lkbkw3oqjk2o</link><description>🔥 You can now add TruffleHog to Burp Suite!&#xA;&#xA;🌐 Install it directly from the BApp Store&#xA; 🔍Scan web traffic for live, verified credentials—active &amp; exploitable&#xA;&#xA; Because secrets don’t just leak in code… 😬&#xA;&#xA;🔗 https://trufflesecurity.com/blog/introducing-trufflehog-s-burp-suite-extension-a-techical-deep-dive</description><pubDate>13 Mar 2025 16:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lkbkw3oqjk2o</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lj6hpf57m22h</link><description> We scanned 400TB of DeepSeek’s training data &amp; found:&#xA;&#xA;🚨 ~12K live API keys &amp; passwords &#xA;🌐 2.76M affected pages&#xA;🔄 One key appeared 57K+ times&#xA;🔑 219 secret types (AWS root keys, Slack webhooks, etc.)&#xA;&#xA;🔗 Full research: https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data</description><pubDate>27 Feb 2025 17:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lj6hpf57m22h</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lip6lu2jos22</link><description>Removing Jeff Bezos from my bed - &#xA;&#xA;Do you expect to find an AWS key in your bed? &#xA;&#xA;We found one, and we removed it. We’re sleeping great now.&#xA;&#xA;🔗 trufflesecurity.com/blog/removing-jeff-bezos-from-my-bed</description><pubDate>21 Feb 2025 16:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lip6lu2jos22</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lgj6xkrt5223</link><description>🐷 Under the Hood of TruffleHog!&#xA;&#xA;⚡ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. 🚀&#xA;&#xA;👉 https://trufflesecurity.com/blog/under-the-hood-the-algorithmic-power-behind-trufflehog-s-secret-scanning-(part-1-of-2)</description><pubDate>24 Jan 2025 20:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lgj6xkrt5223</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lfntn7yvec2v</link><description>🚨Today we are announcing a new OAuth bug that affects millions of accounts&#xA;&#xA;🌟 TLDR: Google’s OAuth login doesn’t protect against someone purchasing a failed startup’s domain and using it to re-create email accounts for former employees&#xA;&#xA; 👉 full blog: https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw</description><pubDate>13 Jan 2025 22:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lfntn7yvec2v</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lf7p6cg4xs2g</link><description>Vigilante Justice on GitHub. 🦇🦸&#xA;&#xA;Here&#39;s how to spray painting on other fraudster&#39;s GitHub Activity Graph.&#xA;&#xA;https://trufflesecurity.com/blog/vigilante-justice-on-github</description><pubDate>08 Jan 2025 08:02 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lf7p6cg4xs2g</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3ldoujd3cuc2s</link><description>🚨 10% of SaaS platforms mishandle GitHub OAuth tokens, opening potential backdoors into corporate accounts. 😱 &#xA;&#xA;⚠️ Extends to Azure, Slack &amp; more—increasing risk with poor token handling.&#xA;&#xA;🛑 The issue isn’t OAuth; it’s how platforms secure tokens.&#xA;&#xA;👉 https://trufflesecurity.com/blog/mishandled-oauth-tokens-open-backdoors</description><pubDate>19 Dec 2024 21:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3ldoujd3cuc2s</guid></item><item><link>https://bsky.app/profile/trufflesec.bsky.social/post/3lcvb4hre442g</link><description>🐷 TruffleHog now decodes APKs to scan for secrets 🚀&#xA;&#xA;💡 Why it matters:&#xA;🔍 APKs often leak secrets, but scanning was slow &amp; complex.&#xA;🔓 Now it’s fast, efficient &amp; scalable.&#xA;📊 Tested on WhatsApp &amp; Facebook Messenger—up to 16.5x faster!&#xA;&#xA;👉https://trufflesecurity.com/blog/cracking-open-apk-files-at-scale</description><pubDate>09 Dec 2024 17:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:7khytha3ck7pxeo6bhpigpwi/app.bsky.feed.post/3lcvb4hre442g</guid></item></channel></rss>