Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

GitGuardian Blog
blog.gitguardian.com > bsideslv-2026

BSides Las Vegas 2026: Following the Trust Relationships Attackers Are Targeting

1+ day, 19+ hour ago   (940+ words) BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it. GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and…...

GitGuardian Blog
blog.gitguardian.com > inside-the-litellm-hack

Inside the LiteLLM Hack: 153GB and 2,488 Organizations

1+ day, 15+ hour ago   (836+ words) Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live. Guillaume is a Cybersecurity Researcher at GitGuardian. He holds a PhD in networking....

GitGuardian Blog
blog.gitguardian.com > ai-agent-identity

Your AI Agents Are Using Your Credentials

2+ day, 13+ hour ago   (912+ words) AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance…...

GitGuardian Blog
blog.gitguardian.com > vault-coverage

Vault Coverage Is the Missing Metric in the NHI Programs

4+ day, 17+ hour ago   (1542+ words) Most vault programs track a numerator without a denominator. See how vault coverage turns secrets management into a measurable, reportable control. GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and has been involved in the…...

GitGuardian Blog
blog.gitguardian.com > keyv-mini-shai-hulud

Mini Shai-Hulud's Latest Wave: 280 New Places

1+ week, 1+ day ago   (882+ words) A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection. He uses…...

GitGuardian Blog
blog.gitguardian.com > 40-million-fake-push-when-spam-commits-took-over-the-public-github

40 Million Fake Commits Flood GitHub’s Public Feed

1+ week, 3+ day ago   (1139+ words) Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection. He uses his…...

GitGuardian Blog
blog.gitguardian.com > credential-harvesting

Credential Harvesting: How Attackers Collect Secrets in 2026

1+ week, 4+ day ago   (1295+ words) Credential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection....

GitGuardian Blog
blog.gitguardian.com > blast-radius-laptop-compromise

Blast Radius After a Laptop Compromise: What to Rotate

2+ week, 2+ day ago   (1327+ words) After a laptop compromise, the hard question is which credentials were on it. See why blast radius scoping is hard, and how to turn it into a revocable list. What happens when an infostealer alert fires or one of your…...

GitGuardian Blog
blog.gitguardian.com > hugging-face-breach-ai-agent-security

Hugging Face Breach: AI Agent Security Lessons | GitGuardian

2+ week, 3+ day ago   (703+ words) OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now. Katie DeMatteis is Director of Content…...

GitGuardian Blog
blog.gitguardian.com > how-to-reduce-time-to-revoke-for-exposed-credentials

How to Measure Time to Revoke for Exposed Credentials

2+ week, 4+ day ago   (1500+ words) Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics. GitGuardian Product Marketer — Ben has worked in cybersecurity since 2020, specializing in security content that developers and security teams actually…...