Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
BSides Las Vegas 2026: Following the Trust Relationships Attackers Are Targeting
1+ day, 19+ hour ago (940+ words) BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it. GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and…...
Inside the LiteLLM Hack: 153GB and 2,488 Organizations
1+ day, 15+ hour ago (836+ words) Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live. Guillaume is a Cybersecurity Researcher at GitGuardian. He holds a PhD in networking....
Your AI Agents Are Using Your Credentials
2+ day, 13+ hour ago (912+ words) AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance…...
Vault Coverage Is the Missing Metric in the NHI Programs
4+ day, 17+ hour ago (1542+ words) Most vault programs track a numerator without a denominator. See how vault coverage turns secrets management into a measurable, reportable control. GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and has been involved in the…...
Mini Shai-Hulud's Latest Wave: 280 New Places
1+ week, 1+ day ago (882+ words) A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection. He uses…...
40 Million Fake Commits Flood GitHub’s Public Feed
1+ week, 3+ day ago (1139+ words) Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection. He uses his…...
Credential Harvesting: How Attackers Collect Secrets in 2026
1+ week, 4+ day ago (1295+ words) Credential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first. As a security researcher at GitGuardian, Gaetan is pioneering innovations in secret detection....
Blast Radius After a Laptop Compromise: What to Rotate
2+ week, 2+ day ago (1327+ words) After a laptop compromise, the hard question is which credentials were on it. See why blast radius scoping is hard, and how to turn it into a revocable list. What happens when an infostealer alert fires or one of your…...
Hugging Face Breach: AI Agent Security Lessons | GitGuardian
2+ week, 3+ day ago (703+ words) OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now. Katie DeMatteis is Director of Content…...
How to Measure Time to Revoke for Exposed Credentials
2+ week, 4+ day ago (1500+ words) Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics. GitGuardian Product Marketer — Ben has worked in cybersecurity since 2020, specializing in security content that developers and security teams actually…...