
Leading AI Companies Keep Leaking Their Own Information on GitHub
Why It Matters
The findings reveal pervasive security gaps at the industry's leading AI players, raising the risk of credential theft and supply‑chain attacks, and underscore the need for robust secret‑management practices across the sector.
Summary
Wiz researchers scanned GitHub repositories associated with the Forbes top‑50 AI companies and discovered that 65% of them expose verified secrets—API keys, tokens and credentials—often hidden in deleted forks, developer repos and gists. Their proprietary “Depth, Perimeter, and Coverage” methodology expands discovery to contributors’ personal repos and targets newer secret types such as those from Tavily, Langchain, Cohere and Pinecone, uncovering leaks traditional scanners miss. When the firms were notified, almost half of the alerts failed to reach a response channel or received no reply. Wiz advises immediate deployment of comprehensive secret‑scanning, prioritisation of proprietary secret formats, and the establishment of dedicated disclosure channels.
Leading AI companies keep leaking their own information on GitHub
Comments
Want to join the conversation?
Loading comments...