Truffle Security

434 posts

Truffle Security banner
Truffle Security

Truffle Security

@trufflesec

The TruffleHog company We find credentials, with open source https://t.co/7CnEqo1inq https://t.co/8vZxthRRXX

Katılım Ocak 2019
1 Takip Edilen4.8K Takipçiler
Truffle Security
Truffle Security@trufflesec·
Claude (and other models) are hacking systems WITHOUT YOU ASKING. That’s what we found across dozens of experiments. When faced with innocent tasks that can only be accomplished via hacking, they often choose to hack. We found this alarming. What does this mean for the future of AI safety? 🚨🚨🚨 🔗trufflesecurity.com/blog/claude-tr…
Truffle Security tweet media
English
8
40
201
81.2K
Truffle Security retweetledi
John Hammond
John Hammond@_JohnHammond·
Google API keys didn't use to be considered "secret," so they're all over the web-- but now they are an open door to Gemini 🫠 Quick rundown video of Truffle Security's really nifty research, almost 3,000 websites exposed.. including Google themselves😅 🔗 youtu.be/XNMHUifKce8
YouTube video
YouTube
John Hammond tweet media
English
7
57
367
49.4K
Truffle Security
Truffle Security@trufflesec·
🚨 Google told devs: API keys aren't secrets. Gemini changed that. 😱 We found ~3,000 public keys silently authenticating to Gemini - exposing private files, cached data & charging for LLM usage 💥Even Google's own keys were vulnerable. 🔗 trufflesecurity.com/blog/google-ap…
Truffle Security tweet media
English
14
72
327
90K
Truffle Security
Truffle Security@trufflesec·
🚨New TruffleHog Detector Alert! 🐷TruffleHog now detects & verifies live JWTs signed with asymmetric public keys 🔒We found hundreds of live secrets for TruffleHog Enterprise customers within hours! 🔗 trufflesecurity.com/blog/truffleho…
Truffle Security tweet media
English
0
3
23
1.5K
Truffle Security
Truffle Security@trufflesec·
🌟Part 2 from Security researcher Luke Marshall is live - the final in his series on Git platform secret exposure. Scanned ~5.6M public GitLab repos with TruffleHog 🐷 🔒 17K+ verified live secrets 💸 $9K+ in bounties 🔗trufflesecurity.com/blog/scanning-…
Truffle Security tweet media
English
0
5
30
1.7K
Truffle Security
Truffle Security@trufflesec·
Security researcher Luke Marshall scanned every public Bitbucket repo (2.6M+) using TruffleHog 🐷 🔍Found 6,212 verified live secrets 💰 Made $10K+ in bug bounties Even uncovered an active #AWS key from 2013 😳 🔗trufflesecurity.com/blog/scanning-…
Truffle Security tweet media
English
1
5
45
7.7K
Rock Pratap Singh (Rocksec)🇮🇳
Rock Pratap Singh (Rocksec)🇮🇳@Rockpratapsingh·
The worst feeling… my frustration is at its peak. Yesterday I reported 2 bugs and today both got marked duplicate — one by 45 sec, the other by 58 sec. And the best part? I reported both within 5 minutes of the program launching on @Bugcrowd. The level of competition is insane.
English
10
0
49
5.3K
ThePrimeagen
ThePrimeagen@ThePrimeagen·
what is happening
Y Combinator@ycombinator

TheHog.ai is the Google Maps for customer acquisition. It finds the most optimized routes to reach your customers and turns scattered data into clear next steps. It's the all-in-one GTM and marketing tool that gives one person the power of an entire sales and marketing team.

English
101
18
1.1K
193.2K
Truffle Security retweetledi
Intel Capital
Intel Capital@intelcapital·
Congrats to @trufflesec on raising $25M in #SeriesB #funding! 🎊With this round, Truffle will expand its detection, verification, and remediation solution and innovation in non-human identity (NHI) protection. Read more in @NickWashburn80 and Sunil Kurkure’s blog post: bit.ly/496daG2
English
4
4
19
1.9K
Truffle Security
Truffle Security@trufflesec·
🚀BIG NEWS! Truffle Security raised a $25M Series B led by @intelcapital & @a16z to accelerate making secrets easier to manage 🐷 Starting today - TruffleHog GCP Analyze maps leaked GCP secrets, their permissions & reach to remediate with confidence 🔗 trufflesecurity.com/press/series-b
Truffle Security tweet media
English
6
5
29
45.6K
Truffle Security
Truffle Security@trufflesec·
⭐️Huge thanks to Adam Reiser of Cisco Talos for helping us harden TruffleHog! 🐷 We’ve updated TruffleHog, improving how untrusted Git repos are handled. 🙌Shoutout to the open-source community for making TruffleHog stronger! 👉trufflesecurity.com/blog/contribut…
Truffle Security tweet media
English
0
0
3
452
Truffle Security
Truffle Security@trufflesec·
⚠️ Supply chain attacks keep stacking up- Salesforce, S1ngularity/NX & more. ⚒️ The same tools attackers use to find secrets are the ones defenders need too. 🐷 That’s why threat intel groups recommend TruffleHog. 🔗 Learn why it shows up in your logs: trufflesecurity.com/blog/truffleho…
Truffle Security tweet media
English
0
0
2
481
Truffle Security
Truffle Security@trufflesec·
🚨Threat actors are targeting Salesforce instances to steal creds hidden in Case objects 🔍 Google Threat Intel advises scanning sensitive data (Cases, Accounts, Users, etc.) with 🐷TruffleHog before attackers do 🔗 trufflesecurity.com/blog/detecting…
Truffle Security tweet media
English
0
2
6
568
Truffle Security
Truffle Security@trufflesec·
🚨 Nx build system hit by a supply-chain attack (8/26). Infected NPM versions stole GitHub tokens, SSH keys, wallets & NPM tokens. ⚠️Later used (8/28–29) to flip private repos public. If you see repos like s1ngularity-repository, revoke tokens ASAP. 🔗stepsecurity.io/blog/supply-ch…
English
0
1
5
692