Security researcher discovers 17,000 secrets in public GitLab repositories



  • A researcher found 17,000 secrets exposed in GitLab Cloud repositories
  • Leaked credentials risk hijacking, cryptomining, and deeper infrastructure compromise
  • Marshall automated scans and earned $9,000 in rewards; some projects are still exposed

A security researcher found thousands of secrets in public GitLab Cloud repositories, demonstrating how software developers inadvertently put their own projects at risk of cyberattacks.

GitLab Cloud is the hosted version of GitLab, a platform that developers use to store code, track issues, run CI/CD pipelines, and collaborate on software projects.



Leave a Comment

Your email address will not be published. Required fields are marked *