Truffle Security
@trufflesec
Followers
4K
Following
255
Media
139
Statuses
427
The TruffleHog company We find credentials, with open source https://t.co/7CnEqo1inq https://t.co/8vZxthRRXX
Joined January 2019
Might we have a word.
2
2
14
Congrats to @trufflesec on raising $25M in #SeriesB #funding! 🎊With this round, Truffle will expand its detection, verification, and remediation solution and innovation in non-human identity (NHI) protection. Read more in @NickWashburn80 and Sunil Kurkure’s blog post:
4
4
19
🚀BIG NEWS! Truffle Security raised a $25M Series B led by @intelcapital & @a16z to accelerate making secrets easier to manage 🐷 Starting today - TruffleHog GCP Analyze maps leaked GCP secrets, their permissions & reach to remediate with confidence 🔗 https://t.co/AXMIVpvKW3
6
5
30
🔒 We’ve been tackling #NHI since before it was NHI. 📷This post, from the pioneers of open-source secret scanning, breaks down what matters when it comes to secrets. 👉 https://t.co/ohfbFmIRrx
0
1
2
⭐️Huge thanks to Adam Reiser of Cisco Talos for helping us harden TruffleHog! 🐷 We’ve updated TruffleHog, improving how untrusted Git repos are handled. 🙌Shoutout to the open-source community for making TruffleHog stronger! 👉 https://t.co/wMsHnS4k7J
0
0
3
⚠️ Supply chain attacks keep stacking up- Salesforce, S1ngularity/NX & more. ⚒️ The same tools attackers use to find secrets are the ones defenders need too. 🐷 That’s why threat intel groups recommend TruffleHog. 🔗 Learn why it shows up in your logs: https://t.co/Vs9CSwdjNe
0
0
2
🚨Threat actors are targeting Salesforce instances to steal creds hidden in Case objects 🔍 Google Threat Intel advises scanning sensitive data (Cases, Accounts, Users, etc.) with 🐷TruffleHog before attackers do 🔗 https://t.co/yhMbvoTfST
0
2
6
🚨 Nx build system hit by a supply-chain attack (8/26). Infected NPM versions stole GitHub tokens, SSH keys, wallets & NPM tokens. ⚠️Later used (8/28–29) to flip private repos public. If you see repos like s1ngularity-repository, revoke tokens ASAP. 🔗 https://t.co/uYvLZRYZDM
stepsecurity.io
s1ngularity attack hijacked Nx package on npm to steal cryptocurrency wallets, GitHub/npm tokens, SSH keys, and environment secrets - the first documented case of malware weaponizing AI CLI tools for...
0
1
5
The #s1ngularity attack second wave is ongoing. Private repositories are turning public with new names. Impacted organizations need to MOVE NOW to rotate their secrets. Use tools like trufflehog to check. Assume everything that went public is compromised. @trufflesec for viz.
1
3
28
☁️Some clouds leak secrets. One stands apart. 🌟Join our 8/26 webinar to see what 🐷TruffleHog found scanning tens of thousands of #AWS, #Azure & #GCP images. 🔗 Register: https://t.co/wgbSGZ3HW7
0
0
8
Meet the Truffle Security team at Booth 5511 @BlackHatEvents. Come by, find the leaked secrets and win a prize. #TruffleHog
0
0
6
🔐 8,437 #GCP images. 147M files. 0 live secrets. ☁️ GCP’s strict image controls show clear results vs. #AWS & #Azure. 🔗 Full CloudQuarry report: https://t.co/YaWIqitffs
0
4
9
Think secrets are gone after a force push? Think again. 🔍We built Force Push Scanner to find secrets in dangling GitHub commits. 🙀Millions are still exposed. 🔗 https://t.co/ZDLgxp1Vmw
1
3
57
🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub. 🔗A guest post by Sharon Brizinov: https://t.co/cjD7XjmLtO
1
19
61
I asked @MayaKaczorowski (former Senior Director @github) about her thoughts about GitHub's identity system. Personally I think managing identity in GitHub is clear as mud.
1
5
13
Here's how to make LLM's self replicate. Embedding LLM's into traditional malware worms. Originally presented by @InsecureNature at @BSidesSF 🧵👇👇👇
1
5
9
Tomorrow I'll be speaking at @BSidesSF at 11:15am. The topic? Aligning light weight AI models to become self replicating ransomware worms. Join me on the IMAX.
1
3
13