What a Supply Chain Attack Is Really After: Your Credentials
Recent campaigns show a consistent pattern: a supply chain attack compromises trusted software to reach the credentials held by developer machines and CI/CD pipelines.
Recent campaigns show a consistent pattern: a supply chain attack compromises trusted software to reach the credentials held by developer machines and CI/CD pipelines.
* The trick matters less than the access. Three 2026 disclosures, GitLost, Claude Code's CVE-2026-21852, and Amazon Q's CVE-2026-12957, show agent manipulation determines less damage than the credentials and permissions the agent can reach. * Secrets exposure keeps
Your security stack is a set of specialists, each guarding one territory. Exposed credentials don't respect the boundaries between them, and 64% of the ones found valid in 2022 were still valid four years later.
AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance blind spot.
OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.
The security perimeter moved from network to identity to the device. Here’s why the developer endpoint is now where credentials concentrate – and the gap it leaves.
Learn why modern identity infrastructure security depends on credential exposure detection, not just directory management, and how to close the gaps that lead to breaches.