Skip to main content
HomeTopicsGitHub

GitHub

We've curated 9 cybersecurity statistics about GitHub to help you understand how vulnerabilities in open-source code and supply chain threats are being addressed in 2025. This insight is crucial for developers and organizations alike!

Showing 1-9 of 9 results

12% of organizations detected employee exposure to malware via GitHub each month in 2025.

Netskope1/13/2026
MalwareUser Behavior

65% of the 50 leading AI companies analyzed had leaked verified secrets on GitHub.

Wiz11/16/2025
AI companyLeaked verified secret

In one specific case (an AI50 Company with no disclosure permission), a HuggingFace token found in a deleted fork allowed access to about 1K private models. The leak also included multiple WeightsAndBiases API keys belonging to organizational employees that leaked training data for many private models

Wiz11/16/2025
AI companyLeaked verified secret

Almost half of the disclosures regarding leaked secrets by leading AI companies on GitHub either failed to reach the target or received no response.

Wiz11/16/2025
AI companyLeaked verified secret

The company with the smallest footprint that still had verified leak instances had 0 public repositories and 14 organization members.

Wiz11/16/2025
AI companyLeaked verified secret

The total valuation of the companies with verified secret leaks is over $400B.

Wiz11/16/2025
AI companyLeaked verified secret

The company with the largest footprint without an exposed secret had 60 public repositories and 28 organization members.

Wiz11/16/2025
AI companyLeaked verified secret

There are a total of 20,000 MCP server implementations on GitHub.

Astrix Security10/15/2025
Model Context Protocol

There are an estimated 20,000 repositories in GitHub implementing open-source Model Context Protocol (MCP) servers.

Astrix Security10/15/2025
Model Context Protocol