Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Truffle Security Co.

Truffle Security Co. Vendor Cyber Rating & Cyber Score

trufflesecurity.com

Our team of career security experts are dedicated to building robust and intelligent software that helps you protect your information. Security is our passion and our primary concern, and all features are developed with best practices in mind. Our flagship product, TruffleHog, runs behind the scenes to scan your environment for secrets like private keys and credentials, so you can protect your data before a breach occurs. We're on a mission to secure sensitive data. https://www.youtube.com/c/TruffleSecurity


TSC A.I CyberSecurity Scoring

TSC
Company Information
Website:http://www.trufflesecurity.com
Employees number:52
Number of followers:3,983
NAICS:541514
Industry Type:Computer and Network Security
Homepage:trufflesecurity.com
TSC Risk Score (AI oriented)
Between 700 and 749
logo
TSCComputer and Network Security
Updated:
04/04/2026
743/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
TSC Global Score (TPRM)
xxxx
logo
TSCComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TSC
TSCModerate
Current Score
743Ba (MODERATE)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
744Before Incident
MAY 2026
743Before Incident
APRIL 2026
743Before Incident
MARCH 2026
743Before Incident
FEBRUARY 2026
747Before Incident
Vulnerability
27 Feb 2026TSC
Google: Google API Keys Leak Sensitive Data Without Warning via Gemini

Google API Keys Expose Gemini AI Endpoints in Legacy Security Flaw

742After Incident
CRITICAL-5
GOO1772173606
Google API Keys Expose Gemini AI Endpoints in Legacy Security Flaw Security researchers at Truffle Security uncovered a critical vulnerability in Google’s API key architecture, where legacy public-facing keys originally designed for low-risk services like Google Maps can silently gain unauthorized access to Gemini AI endpoints. This flaw allows attackers to exploit exposed keys, accessing private files, cached data, and triggering costly AI queries without detection. The issue stems from insecure defaults in Google Cloud Platform (GCP). When developers enable the Generative Language API on an existing project, previously public API keys once considered safe for client-side use are automatically upgraded into sensitive credentials with unrestricted access. Since Google uses a single key format for both public identification and authentication, there is no separation between low-risk and high-risk environments. Exploitation is straightforward: attackers can scrape exposed keys from public code repositories and use them to query Gemini, potentially stealing data or incurring thousands in billable AI usage. The flaw affects thousands of websites, as many developers followed Google’s past guidance to embed API keys directly in client-side code. Google is mitigating the issue by defaulting new keys in AI Studio to Gemini-only access and blocking known leaked credentials. However, organizations must audit projects for unrestricted keys and rotate exposed credentials to prevent exploitation. The incident underscores the risks of retrofitting modern AI capabilities onto outdated cloud security models.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Financial Loss: Thousands in billable AI usageData Compromised: Private files, cached dataSystems Affected: Gemini AI endpoints, Google Cloud Platform projectsOperational Impact: Unauthorized access to AI endpointsBrand Reputation Impact: Risk of brand reputation damage due to data exposure
DATA BREACH
Type Of Data Compromised: Private files, cached dataSensitivity Of Data: High (AI-related data)
JANUARY 2026
747Before Incident
DECEMBER 2025
747Before Incident
NOVEMBER 2025
750Before Incident
Vulnerability
28 Nov 2025TSC
Truffle Security Co.: Public GitLab repositories exposed more than 17,000 secrets

Exposure of 17,000+ Secrets in 5.6 Million Public GitLab Repositories

747After Incident
CRITICAL-3
TRU1764352828
After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains. Luke Marshall used the TruffleHog open-source tool to check the code in the repositories for sensitive credentials like API keys, passwords, and tokens. The researcher previously scanned Bitbucket, where he found 6,212 secrets spread over 2.6 million repositories. He also checked the Common Crawl dataset that is used to train AI models, which exposed 12,000 valid secrets. GitLab is a web-based Git platform used by software developers, maintainers, and DevOps teams to host code, for CI/CD operations, development collaboration, and repository management. Marshall used a GitLab public API endpoint to enumerate every public GitLab Cloud repository, using a custom Python script to paginate through all results and sort them by project ID. This process returned 5.6 million non-duplicate repositories, and their names were sent to an AWS Simple Queue Service (SQS). Next, an AWS Lambda function pulled the repository name from SQS, ran TruffleHog against it, and logged the results. “Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000,” describes Marshall. “This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours.” The total cost for the entire public GitLab Cloud repositories using the above method was $770. The researcher found 17,430 ver
INCIDENT DETAILS -
TYPE
data exposurecredential leakagemisconfiguration
IMPACT
API keyspasswordstokenssensitive credentialsGitLab Cloud public repositoriespotential unauthorized access to systems/servicesrisk of account takeoverssupply chain attackspotential erosion of trust in GitLab's platform securityreputational risk for affected domainshigh (due to exposed credentials)
DATA BREACH
API keyspasswordsauthentication tokensprivate keysdatabase credentialsNumber Of Records Exposed: 17,430 (GitLab) + 6,212 (Bitbucket) + 12,000 (Common Crawl)Sensitivity Of Data: high (credentials with potential for unauthorized access)Data Exfiltration: yes (secrets were publicly accessible)Data Encryption: no (secrets were in plaintext)source code filesconfiguration filesenvironment files (e.g., .env)
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for TSC ?
?
What was TSC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was TSC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was TSC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was TSC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was TSC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was TSC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was TSC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was TSC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was TSC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was TSC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was TSC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on TSC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with TSC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view TSC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?