Please turn JavaScript on

GitGuardian Blog - Take Control of Your Secrets Security

Following GitGuardian Blog - Take Control of Your Secrets Security's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with GitGuardian Blog - Take Control of Your Secrets Security!

GitGuardian Blog - Take Control of Your Secrets Security: GitGuardian Blog - NHI Governance & Secrets Security

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.42 / day

Message History

TL;DRAI agent threat response has layers. Runtime detection watches agents in motion and catches prompt injection, goal hijacking, memory poisoning, and suspicious tool chains. Preventative, pre-runtime controls limit what credentials, systems, and authority an agent can reach before execution begins.Valid credentials within an agent's r...

Read full story

In July 2026, researchers at Noma Labs coaxed GitHub's new Agentic Workflows into leaking data from a private repository. It wasn’t from malware. They created a plausible-looking issue in a public rep...


Read full story

TL;DRMachine-speed attacks: AI agents have collapsed the time between credential discovery and abuse to near-zero, removing the human reaction window defenders used to count on.ChainDrop in numbers: This Shai-Hulud npm worm hijacked publishing access to hit 444 packages downloaded roughly 2 billion times per month, according to Microsoft....

Read full story
TL;DRMultiple locations, one credential: An API key moves from a developer's laptop to a repo, pipeline logs, a ticket, and a teammate's config; each copy carries the same access, and no single tool tracks all five.Every tool has a job. Secrets fall between them: Your security stack is built from specialists, but no single tool is designed to tr...

Read full story

The March compromise of litellm lasted about 40 minutes on PyPI. This week we learned what the attackers stole in that time.

On August 12, 2026,


Read full story