Please turn JavaScript on
GitGuardian Blog - Take Control of Your Secrets Security icon

GitGuardian Blog - Take Control of Your Secrets Security

Following GitGuardian Blog - Take Control of Your Secrets Security's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with GitGuardian Blog - Take Control of Your Secrets Security!

GitGuardian Blog - Take Control of Your Secrets Security: GitGuardian Blog - NHI Governance & Secrets Security

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.44 / day

Message History

TL;DR

The problem: Service account credentials pile up with no clear owner, and teams avoid rotating them for fear of breaking production dependencies nobody has mapped.The checklist: Answer eight questions before rotating: validity, exposure, access scope, consumers, vault location, duplicate copies, ownership, and rollba...

Read full story
TL;DRThe exposure problem: AI-driven development pushed exposed credentials to 1.27 million last year, up 81%, and 64% of secrets confirmed valid in 2022 are still unrevoked as of January 2026.The fix: GitGuardian Public Secrets Monitoring now runs two AI agents and deep analysis over every public GitHub and Docker Hub incident, returning a comp...

Read full story
TL;DRCredentials are the multiplier: OWASP's Top 10 CI/CD Security Risks cover ten distinct trust failures, but exposed or overprivileged credentials (CICD-SEC-6) make nearly every other risk more dangerous once attackers gain a foothold.Attacks are accelerating: Since 2025, worms like Shai-Hulud, Miasma, and ChainDrop have comp...

Read full story
TL;DREndpoint protection means AV or EDR: The term "endpoint protection" almost always refers to antivirus or EDR. Antivirus started as signature-based malware detection; EDR added continuous behavioral monitoring and response. Both are designed to detect and stop malicious activity on the machine.Credential security asks a diff...

Read full story

TL;DR

The Blind Spot: S3 buckets accumulate years of logs, backups, and pipeline output that never get scanned for secrets, and 28% of incidents now originate entirely outside code repositories.The Attack Speed: Attackers used IAM credentials found in a public S3 bucket to reach admin access in just eight minutes, with AI ...

Read full story