An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker
OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.
How to Reduce Time to Revoke for Exposed Credentials
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
Why SAST and DAST Aren't Enough for Secrets Security
Static and dynamic app testing are cornerstones for any comprehensive AppSec program, yet they rarely rise up to the challenges of fully securing modern software. Discover why secrets are one of their critical blind spots.
Why identity-local signals and topology signals are two layers of the same blast radius
The credential with the widest blast radius sometimes has no secret to flag. See how GitGuardian and Anyshift rank risk by what actually breaks.
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
Between early June and July 14, four more supply chain attacks hit npm and PyPI: a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline. Different entry points, one target: the credentials in developer environments and build pipelines.
How to Measure Time to Revoke for Exposed Credentials
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
The Perimeter Moved to the Laptop: From Network, to Identity, to the Developer Endpoint
The security perimeter moved from network to identity to the device. Here’s why the developer endpoint is now where credentials concentrate – and the gap it leaves.
Identity Infrastructure: Why Credentials Are the Layer Directories Don't Secure
Learn why modern identity infrastructure security depends on credential exposure detection, not just directory management, and how to close the gaps that lead to breaches.
What CISA Got Right After Its GitHub Leak: Lessons Every Organization Should Copy
After the CISA GitHub leak, the agency published a candid incident postmortem. Here are six lessons security teams should copy, from secrets scanning to key rotation.
GitGuardian Power for Amazon Kiro: Secrets Detection Built Into the Agent
GitGuardian is now live on the Kiro Powers marketplace. Install the Power once, and Kiro's agent scans for exposed secrets automatically every time it writes or modifies code that handles credentials.
Every Laptop Is a Credential Store: Where Secrets Hide
Cloud keys, shell history, SSH keys, AI agent caches: a complete inventory of where credentials hide on a developer's machine, and why infostealers go looking there.
IEEE Cloud Summit 2026: The Tunnels No One Mapped
Explore cloud security lessons from IEEE Cloud Summit 2026, including agentic AI risks, over-permissioned identities, Kubernetes policy, and forensics.