Guillaume Valadon

Guillaume Valadon

Guillaume is a Cybersecurity Researcher at GitGuardian. He holds a PhD in networking. He likes looking at data and crafting packets. He co-maintains Scapy. And he still remembers what AT+MS=V34 means!

Paris
33 posts
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise

Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise

A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it.

Leaked Kubernetes Secrets: Impact Assessment and Mitigation Strategies

Leaked Kubernetes Secrets: Impact Assessment and Mitigation Strategies

A single leaked Kubernetes credential rarely stays in the cluster. It opens the registry credentials, private Docker images, and private GitHub repositories behind it. In Q1 2026 alone, our detectors caught close to 2,000 new such leaks on GitHub, 28% valid at leak time.

How We Got a CISA GitHub Leak Taken Down in Under a Day

How We Got a CISA GitHub Leak Taken Down in Under a Day

On May 14, GitGuardian found a public GitHub repository called "Private-CISA" — 844 MB of plain-text passwords, AWS tokens, and Entra ID SAML certificates belonging to CISA, exposed since November 2025. Some credentials were still valid. CISA pulled it offline within 26 hours.