Truffle Security (@trufflesec) 's Twitter Profile
Truffle Security

@trufflesec

The TruffleHog company

We find credentials, with open source

tiktok.com/@trufflesecuri…
youtube.com/c/TruffleSecur…

ID: 1081974201781694464

linkhttps://trufflesecurity.com calendar_today06-01-2019 18:02:06

405 Tweet

4,4K Followers

1 Following

Truffle Security (@trufflesec) 's Twitter Profile Photo

🐷 Under the Hood of TruffleHog! ⚡ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. 🚀 👉 trufflesecurity.com/blog/under-the…

🐷 Under the Hood of TruffleHog!

⚡ Part 1 of 2: How Aho-Corasick + CPU optimizations deliver 11-17% faster scans with precomputed keyword matching. 🚀

👉  trufflesecurity.com/blog/under-the…
Truffle Security (@trufflesec) 's Twitter Profile Photo

🔍Webinar: Are LLMs teaching devs to hardcode API keys? 🔑 We tested 10 LLMs & most recommend hardcoding credentials, even in tools like VS Code & ChatGPT 📅 Join us on 2/20 to learn more about the risks & how to stay secure: trufflesecurity.com/webinars/are-l…

🔍Webinar: Are LLMs teaching devs to hardcode API keys?

🔑 We tested 10 LLMs & most recommend hardcoding credentials, even in tools like VS Code & ChatGPT

📅 Join us on 2/20 to learn more about the risks & how to stay secure: trufflesecurity.com/webinars/are-l…
Truffle Security (@trufflesec) 's Twitter Profile Photo

Removing Jeff Bezos from my bed - Do you expect to find an AWS key in your bed? We found one, and we removed it. We’re sleeping great now. 🔗trufflesecurity.com/blog/removing-…

Removing Jeff Bezos from my bed -

Do you expect to find an AWS key in your bed?

We found one, and we removed it. We’re sleeping great now.

🔗trufflesecurity.com/blog/removing-…
Truffle Security (@trufflesec) 's Twitter Profile Photo

We scanned 400TB of DeepSeek’s training data & found: 🚨 ~12K live API keys & passwords 🌐 2.76M affected pages 🔄 One key appeared 57K+ times 🔑 219 secret types (AWS root keys, Slack webhooks, etc.) 🔗 Full research: trufflesecurity.com/blog/research-…

We scanned 400TB of DeepSeek’s training data & found:

🚨 ~12K live API keys & passwords 
🌐 2.76M affected pages
🔄 One key appeared 57K+ times
🔑 219 secret types (AWS root keys, Slack webhooks, etc.)
🔗 Full research: trufflesecurity.com/blog/research-…
Truffle Security (@trufflesec) 's Twitter Profile Photo

🔥 You can now add TruffleHog to Burp Suite! 🌐 Install it directly from the BApp Store 🔍Scan web traffic for live, verified credentials—active & exploitable Because secrets don’t just leak in code… 😬 Big Thanks to PortSwigger ! 🙌 🔗trufflesecurity.com/blog/introduci…

🔥 You can now add TruffleHog to Burp Suite!

🌐 Install it directly from the BApp Store
 🔍Scan web traffic for live, verified credentials—active & exploitable

 Because secrets don’t just leak in code… 😬

Big Thanks to <a href="/PortSwigger/">PortSwigger</a> ! 🙌

🔗trufflesecurity.com/blog/introduci…
Truffle Security (@trufflesec) 's Twitter Profile Photo

🚨 Are LLMs teaching devs to hardcode API keys? 🔑 🔍Our research shows most AI coding assistants recommend insecure practices. Our on-demand webinar highlights the risks, their impact in IDEs like VS Code, & how to stay secure! 📺 Watch now: trufflesecurity.com/webinars/are-l…

🚨 Are LLMs teaching devs to hardcode API keys? 🔑
🔍Our research shows most AI coding assistants recommend insecure practices. 

Our on-demand webinar highlights the risks, their impact in IDEs like VS Code, &amp; how to stay secure!

📺 Watch now: trufflesecurity.com/webinars/are-l…
Truffle Security (@trufflesec) 's Twitter Profile Photo

🐷Want the latest on TruffleHog, security research, news, and events? 🔐 Stay up-to-date with our newsletter. 🔗 Sign up here: trufflesecurity.com/newsletter

🐷Want the latest on TruffleHog, security research, news, and events? 🔐

Stay up-to-date with our newsletter.

🔗 Sign up here: trufflesecurity.com/newsletter
Resourcely (@resourcely) 's Twitter Profile Photo

On episode 2 of Security Wisdom, Travis McPeak was joined by Dylan of Truffle Security, where they covered crafting compelling security narratives. Get the full episode here: resourcely.io/post/security-…

Tal Be'ery (@talbeerysec) 's Twitter Profile Photo

The $64k Bounty: Automating secret extraction from GitHub to win $64K in bounties. Loved the way Sharon glued his GitHub internals knowledge, existing tools (Truffle Security trufflehog), cloud and AI to automate at scale. medium.com/@sharon.brizin…

Dylan (@insecurenature) 's Twitter Profile Photo

Tomorrow I'll be speaking at BSidesSF at 11:15am. The topic? Aligning light weight AI models to become self replicating ransomware worms. Join me on the IMAX.

Dylan (@insecurenature) 's Twitter Profile Photo

I asked Maya Kaczorowski (former Senior Director GitHub) about her thoughts about GitHub's identity system. Personally I think managing identity in GitHub is clear as mud.

Truffle Security (@trufflesec) 's Twitter Profile Photo

🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub. 🔗A guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-pos…

🔍Accessing 15 million "Permanently deleted" commits at scale across GitHub.

🔗A guest post by Sharon Brizinov: trufflesecurity.com/blog/guest-pos…
Truffle Security (@trufflesec) 's Twitter Profile Photo

Think secrets are gone after a force push? Think again. 🔍We built Force Push Scanner to find secrets in dangling GitHub commits. 🙀Millions are still exposed. 🔗 trufflesecurity.com/blog/how-to-sc…

Think secrets are gone after a force push? Think again.

🔍We built Force Push Scanner to find secrets in dangling GitHub commits.

🙀Millions are still exposed.

🔗 trufflesecurity.com/blog/how-to-sc…
Truffle Security (@trufflesec) 's Twitter Profile Photo

🔐 8,437 #GCP images. 147M files. 0 live secrets. ☁️ GCP’s strict image controls show clear results vs. #AWS & #Azure. 🔗 Full CloudQuarry report: trufflesecurity.com/blog/guest-pos…

🔐 8,437 #GCP  images. 147M files. 0 live secrets.

☁️ GCP’s strict image controls show clear results vs. #AWS &amp; #Azure.

🔗 Full CloudQuarry report: trufflesecurity.com/blog/guest-pos…