Content Quality: Well-structured News piece (692 words, within the 400-1200 range). Clear Overview, What We Know, What We Don't Know. Results are consistently attributed to Truffle Security rather than stated as independent fact. No named victims or live credentials; the oldest credential is described only generically (Erlang web server config) and Truffle's decision not to name repositories is reported.
Source Verification: Read both snapshots from disk via gunzip. source-0.html.gz (trufflesecurity.com post dated September 29, 2026, status 200, 436,596 bytes, suspicious_patterns null) is the full real post. Confirmed verbatim: 543,699 unique credentials still authenticating when tested 27-28 July 2026; median 784 days in a public default branch; The Stack v3, 224,553,295 repositories and 58,467,468,698 files, crawl closed 7 August 2025; no commit history, file last-modified timestamp used as leak date and it 'errs in a useful direction' (ages younger than truth); oldest credential last touched 13 June 2009, valid 16.1 years later, Erlang web server config, repositories not named; density 3.72 (2014), 9.54 (2022), 11.09 (2023), 11.62 (2025, highest); more than double the 221,303 Hugging Face figure; push protection default 29 February 2024; 199,843 / 36.8%; protected group -53% vs unprotected -7% over twelve months either side; 51.8% connection string, Google API key or private key not blocked by default; 31,374 live Gemini keys with median leak date February 2025; per-provider counts (npm 101,886/1, GitHub 73,048/260, GCP service accounts 126,963/69,041, Postgres 12,985/11,465); partner program 'does not require partners to revoke anything'; quotes 'Nobody revokes a Postgres URL, and almost everything does.' and 'Treat a committed credential as burned the moment it lands, whether or not anything flagged it. Rotate first, clean up the history second.' all verbatim; caveats (ramp March to July 2024, short-lived credential trend 'cannot be ruled out') verbatim. source-1.html.gz (BleepingComputer, Bill Toulas, September 30, 2026) is flagged archive_fallback: true, but the content is a genuine Wayback Machine capture (20261003021521) of the full article text, not a Cloudflare challenge or stub page; it contains the complete story. Confirmed: 'More than 543,000 credentials ... were still valid in July', 784-day median, 199,843 / 36.8%, 'Push Protection appears effective within its coverage', and the quote 'they don't reveal what percentage of those secrets are actually stolen and abused by attackers.' Both URLs in article.sources match body links.
Factual Accuracy: All specifics trace to a cited source. Density-year discrepancy: BleepingComputer says 3.72 per million files in 2015, Truffle's post says 2014. The article uses 2014 and attributes the figure to Truffle Security, which is supported by the primary source; the BleepingComputer secondary-report 2015 appears to be a reporter error and the article does not assert a year without source support. Minor omissions (not errors): Truffle notes 2025 covers only seven months; the 51.8% figure and 53% fall are Truffle's own derived statistics.
Overall Assessment: Accurate, well-sourced, appropriately attributed vendor research report. Approve without corrections.