40 Million Fake Push: When Spam Commits Took Over The Public GitHub
Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand.
Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand.
Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand.
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it.
Credential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first.
After a laptop compromise, the hard question is which credentials were on it. See why blast radius scoping is hard, and how to turn it into a revocable list.
OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
Static and dynamic app testing are cornerstones for any comprehensive AppSec program, yet they rarely rise up to the challenges of fully securing modern software. Discover why secrets are one of their critical blind spots.
The credential with the widest blast radius sometimes has no secret to flag. See how GitGuardian and Anyshift rank risk by what actually breaks.
Between early June and July 14, four more supply chain attacks hit npm and PyPI: a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline. Different entry points, one target: the credentials in developer environments and build pipelines.
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
The security perimeter moved from network to identity to the device. Here’s why the developer endpoint is now where credentials concentrate – and the gap it leaves.
Learn why modern identity infrastructure security depends on credential exposure detection, not just directory management, and how to close the gaps that lead to breaches.