Gaetan Ferry

Gaetan Ferry

As a security researcher at GitGuardian, I focus on pioneering innovations in secret detection. I use my offensive security and Red Team background to improve our approach to cybersecurity.

5 posts
Website
Security First, Transparency Always: Inside GitGuardian’s Responsible Disclosure Process

Security First, Transparency Always: Inside GitGuardian’s Responsible Disclosure Process

In the past 6 months, our security research team disclosed 24 critical vulnerabilities. Most have been successfully remediated. Our team's contributions to cybersecurity have been formally recognized, with our researchers being listed in both Bayer's and Oracle's Security Researcher Hall of Fame.

The Secret to Your Artifactory: Inside The Attacker Kill-Chain

The Secret to Your Artifactory: Inside The Attacker Kill-Chain

Artifactory token leaks are not the most common, but they pose significant risks, exposing sensitive assets and enabling supply chain attacks. This article explores the dangers of leaked tokens and proposes mitigation strategies, including token scoping and implementing least privilege policies.

The secret to your Artifactory: A Deep Dive into Critical Exposures

The secret to your Artifactory: A Deep Dive into Critical Exposures

While Artifactory tokens aren't the most common leaked secrets, GitGuardian's research reveals their critical nature in corporate environments. Recent investigations across major industries show how these tokens frequently expose sensitive resources through build configurations and DevOps code.

The Ultralytics Supply Chain Attack: Connecting the Dots with GitGuardian’s Public Monitoring Data

The Ultralytics Supply Chain Attack: Connecting the Dots with GitGuardian’s Public Monitoring Data

On December 4, 2024, the Ultralytics Python module was backdoored to deploy a cryptominer. Using GitGuardian’s data, we reconstructed deleted commits, connecting the dots with the initial analysis. This investigation highlights the value of GitGuardian’s data in understanding supply chain attacks.

arrow-down