GitHub adds enterprise public monitoring for secrets leaked across public GitHub content

CyberOGZ analysis of GitHub’s July 1 public monitoring launch: the feature closes a blind spot where company tokens leak from personal forks, public issues, or unrelated repos. Attribution uses committer email on verified domains and GitHub identity graph. GitHub also added validity checks for Asana, IBM Cloud IAM, and MessageBird API keys on the same date.