all tags
AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

Agentic AI Security: Credentials and Permissions Define the Blast Radius

* The trick matters less than the access. Three 2026 disclosures, GitLost, Claude Code's CVE-2026-21852, and Amazon Q's CVE-2026-12957, show agent manipulation determines less damage than the credentials and permissions the agent can reach. * Secrets exposure keeps

Your AI Agents Are Using Your Credentials

Your AI Agents Are Using Your Credentials

AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance blind spot.

Start your journey to secrets-free source code

And keep your secrets out of sight