|
By Soujanya Ain
Antivirus and EDR catch malicious behavior on a machine. Neither tells you which valid credentials are exposed on it right now. That's credential security, a distinct job that finds exposed secrets and helps fix them before attackers do.
|
By Dwayne McDaniel
S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.
|
By Dwayne McDaniel
AI agent threat response starts before runtime. See why pre-runtime credential controls stop agent misuse that runtime detection can only observe.
|
By Katie DeMatteis
In July 2026, researchers at Noma Labs coaxed GitHub's new Agentic Workflows into leaking data from a private repository. It wasn’t from malware. They created a plausible-looking issue in a public repository containing instructions for the agent to retrieve information from other repositories in the organization. After testing variations of the prompt, they found that adding one word, "Additionally," was enough to get past GitHub's guardrails.
|
By Dwayne McDaniel
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse.
|
By Katie DeMatteis
Your security stack is a set of specialists, each guarding one territory. Exposed credentials don't respect the boundaries between them, and 64% of the ones found valid in 2022 were still valid four years later.
|
By Dwayne McDaniel
BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it.
|
By Guillaume Valadon
Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live.
|
By Katie DeMatteis
AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance blind spot.
|
By Dwayne McDaniel
Most vault programs track a numerator without a denominator. See how vault coverage turns secrets management into a measurable, reportable control.
|
By GitGuardian
GitGuardian's validity-override API lets security and engineering teams tell GitGuardian whether an exposed credential is actually valid, even when automatic checks mark it as Failed to Check. Secrets tied to internal services, private APIs, or systems GitGuardian cannot reach often fall into this category. GitGuardian automatically validates most supported credential types, but when it cannot, teams can now perform their own validation and feed the result back into the platform.
|
By GitGuardian
A single compromised laptop can mean weeks of manual credential hunting, or hours of clear, prioritized action. See how GitGuardian Developer Endpoint Protection inventories every credential on a developer's machine so your security team can map the blast radius fast. When an attacker compromises a developer laptop, traditional endpoint tools cannot tell you what credentials were exposed.
|
By GitGuardian
Every developer laptop is a credential store: secrets hide in.env files, config files, and shell history, and every AI agent on the machine keeps adding more. Most teams already scan repositories and CI pipelines for secrets, but a secret lands on the laptop long before it reaches either one, and that's the place nobody scans. GitGuardian's Developer Endpoint Protection closes that gap.
|
By GitGuardian
Dwayne chatted with some devs at this year.
|
By GitGuardian
ggshield v1.53.0 introduces ggshield machine setup, a consistent way to configure ggshield no matter how it was installed. Set up AI hooks for every detected AI coding assistant, install global git pre-commit/pre-push hooks, and deploy a honeytoken on the endpoint. You have full control, and we have options to customize which features you want to skip. This release also includes ggshield machine doctor, a read-only command that checks that the machine's ggshield protections are correctly set up, letting you know what steps to take if it encounters an issue.
|
By GitGuardian
Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.
|
By GitGuardian
Every secret leak matters, but not every incident needs the same level of alerting. GitGuardian’s new Smart Notifiers let teams define per-channel rules so notifications are only sent for the incidents that matter most, using filters like severity, ML risk score, validity, secret type, and GitGuardian tags. This is available now for custom webhooks, Slack, and Microsoft Teams. We will be adding support for ServiceNow, Jira, Splunk, PagerDuty, Discord, and broader email filtering coming next.
|
By GitGuardian
This white paper outlines our Secrets Management Maturity Model, a model to help your organization make sense of its actual posture and how to improve it.
|
By GitGuardian
In this report from Forrester, you will learn how to get better at using Application Security Testing to heighten your developers' security senses.
|
By GitGuardian
Discover Application Security solutions to further secure the SDLC by implementing automated secrets detection in the DevOps pipeline.
|
By GitGuardian
In this document, we go beyond classical definitions of DevSecOps to express our vision of an emerging collaboration between Developers, AppSec, and Ops teams: the AppSec Shared Responsibility Model.
- September 2026 (1)
- August 2026 (19)
- July 2026 (13)
- June 2026 (33)
- May 2026 (26)
- April 2026 (25)
- March 2026 (14)
- February 2026 (11)
- January 2026 (16)
- December 2025 (20)
- November 2025 (14)
- October 2025 (16)
- September 2025 (18)
- August 2025 (14)
- July 2025 (10)
- June 2025 (12)
- May 2025 (12)
- April 2025 (18)
- March 2025 (14)
- February 2025 (10)
- January 2025 (19)
- December 2024 (18)
- November 2024 (11)
- October 2024 (15)
- September 2024 (18)
- August 2024 (11)
- July 2024 (18)
- June 2024 (15)
- May 2024 (14)
- April 2024 (17)
- March 2024 (22)
- February 2024 (18)
- January 2024 (18)
- December 2023 (20)
- November 2023 (12)
- October 2023 (14)
- September 2023 (13)
- August 2023 (20)
- July 2023 (14)
- June 2023 (22)
- May 2023 (21)
- April 2023 (15)
- March 2023 (23)
- February 2023 (13)
- January 2023 (13)
- December 2022 (11)
- November 2022 (3)
- October 2022 (5)
- August 2022 (2)
- July 2022 (1)
GitGuardian is the code security platform for the DevOps generation. With automated secrets detection and remediation, our platform enables Dev, Sec, and Ops to advance together towards the Secure Software Development Lifecycle.
Secure your software development lifecycle with enterprise-grade secrets detection. Eliminate blind spots with our automated, battle-tested detection engine:
- There’s no secret we can’t find: With hundreds of built-in secret detectors scanning thousands of git repositories, GitGuardian brings everything to light. Build custom detectors to enhance your scans for secrets unique to your organization.
- Precise, real-time detection without the hassle: High-efficiency detection proven by billions of commits. GitGuardian is fast, robust, and battle-tested — we’ve scanned over 3 billion commits pushed to public GitHub repositories since 2018.
- Remediation in hours, not days: GitGuardian unites developer and security teams with cross-functional data for in-depth investigation and remediation. Enable shift-left testing using your existing systems, teams, and processes.
Keep secrets out of your source code.