01.02.2024 Views

The Cyber Defense eMagazine February Edition for 2024

Cyber Defense eMagazine February Edition for 2024 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! 155 page February Edition fully packed with some of our best content. Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

Cyber Defense eMagazine February Edition for 2024 #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! 155 page February Edition fully packed with some of our best content. Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

* How widespread is secrets sprawl in PyPI?<br />

At GitGuardian, we worked with security researcher Tom Forbes to scan every PyPI project <strong>for</strong> embedded<br />

secrets. PyPI, <strong>The</strong> Python Package Index, serves the Python community as the official 3rd party package<br />

management plat<strong>for</strong>m. We analyzed over 450,000 projects containing over 9.4 million files across 5<br />

million released versions. This is what we found:<br />

- Total unique secrets found: 3,938<br />

- Unique secrets found to be valid: 768<br />

- Total occurrences of secrets across all releases: 56,866<br />

- Projects containing at least one unique secret: 2,922<br />

- Individual types of secrets detected: 151<br />

Caption: Distinct secrets by detector over time<br />

*<strong>The</strong> files containing the most secrets<br />

Given the research was on Python code, it should not be a surprise that files with the extension `.py`<br />

were the number one source <strong>for</strong> hardcoded credentials. Next most common were configuration and<br />

documentation files such as `.JSON` and `.yml` files. We also found valid secrets in some unexpected<br />

places, such as 209 README files and test folders with 675 unique secrets.<br />

Most common types of files other than .py containing a hardcoded secret in PyPI packages<br />

<strong>Cyber</strong> <strong>Defense</strong> <strong>eMagazine</strong> – <strong>February</strong> <strong>2024</strong> <strong>Edition</strong> 70<br />

Copyright © <strong>2024</strong>, <strong>Cyber</strong> <strong>Defense</strong> Magazine. All rights reserved worldwide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!