trufflesec Profile Banner
Truffle Security Profile
Truffle Security

@trufflesec

Followers
4K
Following
237
Media
132
Statuses
415

The TruffleHog company We find credentials, with open source https://t.co/7CnEqo1inq https://t.co/8vZxthRRXX

Joined January 2019
Don't wanna be here? Send us removal request.
@trufflesec
Truffle Security
3 years
We're so happy to Open Source TruffleHog V3!
4
69
266
@trufflesec
Truffle Security
16 days
🔐 8,437 #GCP images. 147M files. 0 live secrets. ☁️ GCP’s strict image controls show clear results vs. #AWS & #Azure. 🔗 Full CloudQuarry report:
Tweet media one
0
3
10
@trufflesec
Truffle Security
23 days
Think secrets are gone after a force push? Think again. 🔍We built Force Push Scanner to find secrets in dangling GitHub commits. 🙀Millions are still exposed. 🔗
Tweet media one
1
3
56
@trufflesec
Truffle Security
1 month
🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub. 🔗A guest post by Sharon Brizinov:
Tweet media one
1
18
58
@trufflesec
Truffle Security
3 months
RT @InsecureNature: I asked @MayaKaczorowski (former Senior Director @github) about her thoughts about GitHub's identity system. Persona….
0
5
0
@trufflesec
Truffle Security
3 months
Full 30 minute talk:.
1
0
1
@trufflesec
Truffle Security
3 months
Here's how to make LLM's self replicate. Embedding LLM's into traditional malware worms. Originally presented by @InsecureNature at @BSidesSF . 🧵👇👇👇
Tweet media one
1
4
9
@trufflesec
Truffle Security
3 months
May your secrets be with you! #MayTheFourthBeWithYou #TruffleHog
Tweet media one
2
2
15
@trufflesec
Truffle Security
3 months
RT @InsecureNature: Tomorrow I'll be speaking at @BSidesSF at 11:15am. The topic? . Aligning light weight AI models to become self replicat….
0
3
0
@trufflesec
Truffle Security
3 months
RT @TalBeerySec: The $64k Bounty: Automating secret extraction from GitHub to win $64K in bounties. Loved the way Sharon glued his @github….
Tweet card summary image
medium.com
TL;DR — I built an automation that cloned and scanned tens of thousands of public GitHub repos for leaked secrets. For each repository I…
0
3
0
@trufflesec
Truffle Security
4 months
RT @Resourcely: On episode 2 of Security Wisdom, @travismcpeak was joined by @InsecureNature of @trufflesec, where they covered crafting co….
0
2
0
@trufflesec
Truffle Security
4 months
🐷Want the latest on TruffleHog, security research, news, and events? 🔐. Stay up-to-date with our newsletter. 🔗 Sign up here:
Tweet media one
0
1
5
@trufflesec
Truffle Security
5 months
🚨 Are LLMs teaching devs to hardcode API keys? 🔑.🔍Our research shows most AI coding assistants recommend insecure practices. Our on-demand webinar highlights the risks, their impact in IDEs like VS Code, & how to stay secure!. 📺 Watch now:
Tweet media one
0
1
9
@trufflesec
Truffle Security
5 months
🚨 🚨 A quick word the:.⚫ TruffleHog Chrome Extension.⚫ TruffleHog burp plugin.From @InsecureNature
3
9
79
@trufflesec
Truffle Security
5 months
🔥 You can now add TruffleHog to Burp Suite!. 🌐 Install it directly from the BApp Store. 🔍Scan web traffic for live, verified credentials—active & exploitable. Because secrets don’t just leak in code… 😬. Big Thanks to @PortSwigger ! 🙌. 🔗
Tweet media one
3
60
235
@trufflesec
Truffle Security
5 months
We scanned 400TB of DeepSeek’s training data & found:. 🚨 ~12K live API keys & passwords .🌐 2.76M affected pages.🔄 One key appeared 57K+ times.🔑 219 secret types (AWS root keys, Slack webhooks, etc.).🔗 Full research:
Tweet media one
27
149
524
@trufflesec
Truffle Security
5 months
Removing Jeff Bezos from my bed -. Do you expect to find an AWS key in your bed?. We found one, and we removed it. We’re sleeping great now. 🔗
Tweet media one
3
8
24
@trufflesec
Truffle Security
6 months
🔍Webinar: Are LLMs teaching devs to hardcode API keys?. 🔑 We tested 10 LLMs & most recommend hardcoding credentials, even in tools like VS Code & ChatGPT. 📅 Join us on 2/20 to learn more about the risks & how to stay secure:
Tweet media one
1
1
8
@trufflesec
Truffle Security
6 months
🐷 Under the Hood of TruffleHog!. ⚡ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. 🚀. 👉
Tweet media one
0
4
14
@trufflesec
Truffle Security
7 months
🚨 Today we are announcing a new Oauth bug that affects millions of accounts. TLDR: Google’s OAuth login doesn’t protect against someone purchasing a failed startup’s domain and using it to re-create email accounts for former employees. 👇 full blog 👇👇.
Tweet media one
7
63
152