trufflesec Profile Banner
Truffle Security Profile
Truffle Security

@trufflesec

Followers
4K
Following
224
Statuses
397

The TruffleHog company We find credentials, with open source https://t.co/7CnEqo1inq https://t.co/8vZxthRRXX

Joined January 2019
Don't wanna be here? Send us removal request.
@trufflesec
Truffle Security
3 years
We're so happy to Open Source TruffleHog V3!
4
69
262
@trufflesec
Truffle Security
18 days
๐Ÿท Under the Hood of TruffleHog! โšก Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. ๐Ÿš€ ๐Ÿ‘‰
Tweet media one
0
4
12
@trufflesec
Truffle Security
25 days
@shannonNullCode We did. Check out this blog for more info:
0
0
1
@trufflesec
Truffle Security
29 days
๐Ÿšจ Today we are announcing a new Oauth bug that affects millions of accounts TLDR: Googleโ€™s OAuth login doesnโ€™t protect against someone purchasing a failed startupโ€™s domain and using it to re-create email accounts for former employees ๐Ÿ‘‡ full blog ๐Ÿ‘‡๐Ÿ‘‡
Tweet media one
6
64
148
@trufflesec
Truffle Security
2 months
Vigilante Justice on GitHub. ๐Ÿฆ‡๐Ÿฆธ Here's how to spray painting on other fraudster's GitHub Activity Graph.
Tweet media one
1
5
12
@trufflesec
Truffle Security
2 months
๐Ÿšจ 10% of SaaS platforms mishandle GitHub OAuth tokens, opening potential backdoors into corporate accounts. ๐Ÿ˜ฑ โš ๏ธ Extends to Azure, Slack & moreโ€”increasing risk with poor token handling. ๐Ÿ›‘ The issue isnโ€™t OAuth; itโ€™s how platforms secure tokens. ๐Ÿ‘‰
Tweet media one
0
2
10
@trufflesec
Truffle Security
2 months
๐Ÿšจ LLMs are teaching developers to hardcode API keys ๐Ÿ”‘ We tested 10 LLMs & most recommend hardcoding credentials, even in tools like VS Code & ChatGPT. โš ๏ธ The risk? Devs might blindly follow this insecure advice. ๐Ÿ” Read the research:
Tweet media one
0
1
10
@trufflesec
Truffle Security
2 months
๐Ÿท TruffleHog now decodes APKs to scan for secrets ๐Ÿš€ ๐Ÿ’ก Why it matters: ๐Ÿ” APKs often leak secrets, but scanning was slow & complex. ๐Ÿ”“ Now itโ€™s fast, efficient, & scalable. ๐Ÿ“Š Tested on WhatsApp & Facebook Messengerโ€”up to 16.5x faster! ๐Ÿ‘‰
Tweet media one
3
57
219
@trufflesec
Truffle Security
2 months
๐Ÿšจ Calling all security researchers! Truffle Securityโ€™s CFP is open ๐ŸŽ‰ ๐Ÿ’ก Have a project idea? Get $ and be featured on our blog! ๐ŸŒŸFocus: Leaked Secrets | AppSec | IAM | Open-source ๐Ÿ‘‰
Tweet media one
0
4
4
@trufflesec
Truffle Security
3 months
๐ŸŽ‰ Hacktoberfest 2024 Winners! ๐ŸŽ‰ ๐Ÿ† 1st: sahil9001 ๐Ÿฅˆ 2nd: fumblehool, 0x2b3bfa0, rgmz ๐Ÿš€ 15 PRs submitted to boost TruffleHog detectors. ๐ŸŒŸ Big thanks to all contributors! Letโ€™s keep building! ๐Ÿ‘‰
Tweet media one
0
2
5
@trufflesec
Truffle Security
3 months
๐ŸŽƒ This Halloween, we're exposing the scariest places your secrets might still be hiding - including GitHubโ€™s ghostly branches, Azureโ€™s dark corners, and Postman's haunted workspaces! ๐Ÿ‘ป ๐Ÿ’€Find out 7 spooky spots your secrets leak online:
Tweet media one
0
3
5
@trufflesec
Truffle Security
4 months
๐Ÿ”‘ Private Key Reuse: Itโ€™s everywhere! ๐Ÿ” We analyzed 7B+ TLS certs: 10% reuse private keys! ๐Ÿ‘€ We also reviewed 65M GitHub SSH keys: 2% had key reuse issues! ๐Ÿ”“ Reused keys = attackers can impersonate servers, decrypt data, & hijack sessions. ๐Ÿ‘‰
0
1
11
@trufflesec
Truffle Security
4 months
๐Ÿท TruffleHog automagically Scans Encoded & Archived Data for Secrets! ๐Ÿ”Detects secrets in encoded formats (Base64, UTF-8) & archived files (.zip, .tar). ๐Ÿ”Quickly uncover hidden AWS keys and more! ๐Ÿ”—For details & examples:
Tweet media one
0
2
13
@trufflesec
Truffle Security
4 months
RT @geeknik: ๐Ÿšจ Secrets lurk in your code, waiting to be found! ๐Ÿ” TruffleHog hunts them down, but remember: ignoring security is like leavinโ€ฆ
0
1
0
@trufflesec
Truffle Security
4 months
๐Ÿšจ Developers often leak data when open-sourcing on GitHub! ๐Ÿ› ๏ธ ๐Ÿ˜จ๐Ÿ”Even squashing git history doesnโ€™t hide โ€œdanglingโ€ dataโ€”it can still be accessed with the SHA-1 hash. ๐Ÿ›‘Avoid pitfalls & keep your data secure!๐Ÿ”’ โžก๏ธ Check out our open-sourcing tips:
Tweet media one
0
4
7
@trufflesec
Truffle Security
4 months
RT @InsecureNature: I had the privilege of a quick cameo in @_JohnHammond 's recent video, where he covered @trufflesec 's Private and Deleโ€ฆ
0
1
0
@trufflesec
Truffle Security
4 months
RT @InsecureNature: Thanks for sharing our (@trufflesec 's) research! More to come soon, too...
0
1
0
@trufflesec
Truffle Security
4 months
๐Ÿ๐Ÿ‚ Hacktoberfest 2024 is here! ๐Ÿท Join Truffle Security's Detector Improvement Competition! ๐Ÿ”น Fork TruffleHog ๐Ÿ”น Improve a detector ๐Ÿ”น Submit your PR ๐ŸŽ Prizes: MacBook Air, Timbuk2 Backpack, TruffleHog swag! ๐Ÿ—“๏ธ Oct 1 - Oct 31 ๐Ÿ‘‰
Tweet media one
0
7
12
@trufflesec
Truffle Security
5 months
๐ŸŒŸ Security researchers, got a groundbreaking idea? ๐Ÿ’ก ๐Ÿท Truffle Security sponsors 2 projects/month! Accepted proposals receive ๐Ÿ’ฐ and are featured on our blog. ๐Ÿ”‘ Focus: Leaked Secrets | AppSec | IAM | Open-source ๐Ÿ‘‰
Tweet media one
0
1
5
@trufflesec
Truffle Security
5 months
Huge shoutout to to the speakers giving these talks: @amichaishulman @Cassie_Crossley @francoisproulx @InsecureNature @JoeLeonJr @sandrogauci and Ofir Yakobi & Shir Sadon from @orcasec 2/2
0
1
3