Thomas Segura

Thomas Segura

I'm a technical writer with a strong background in cybersecurity and software engineering. I value curiosity, accuracy, originality, and openness in everything I do.

67 posts
Website
AI and Cybersecurity in 2024 - What's Changing and Why It Matters

AI and Cybersecurity in 2024 - What's Changing and Why It Matters

Tired of the AI hype? We get it. Our latest blog takes a no-nonsense look at AI in 2024's cybersecurity – just the facts and some thoughtful insights. No earth-shattering revelations, just a decent read for your coffee break.

Microsoft AI involuntarily exposed a secret giving access to 38TB of confidential data for 3 years

Microsoft AI involuntarily exposed a secret giving access to 38TB of confidential data for 3 years

Discover how an overprovisioned SAS token exposed a massive 38TB trove of private data on GitHub for nearly three years. Learn about the misconfiguration, security risks, and mitigation strategies to protect your sensitive assets.

Why it's urgent to deal with your hardcoded secrets

Why it's urgent to deal with your hardcoded secrets

The figures are precise: stolen credentials remain the most common cause of a data breach. So how are there still thousands of hardcoded secrets hiding in source code, CI/CD pipelines, or Docker images, and, more importantly, how should we deal with them?

The Art of Protecting Secrets: Eight Essential Concepts for SecOps Practitioners

The Art of Protecting Secrets: Eight Essential Concepts for SecOps Practitioners

Secrets management is an art, and mastering it requires a deep understanding of security protocols, meticulous attention to detail, and a proactive approach to staying ahead of threats. In this blog, we present you with eight essential concepts to enhance your credential management strategy.

How to Create and Use Honeytokens: Step-by-Step Instructions

How to Create and Use Honeytokens: Step-by-Step Instructions

Learn how to create, test and deploy GitGuardian honeytokens to detect security breaches, strengthen supply chain security, and prevent code leakage. Find out where to place honeytokens to effectively deceive attackers and protect your assets.

Voice of Practitioners:  The State of Secrets in AppSec

Voice of Practitioners: The State of Secrets in AppSec

Our latest report gathered answers from 507 IT and security decision-makers to study awareness about the risks posed by secrets sprawl and operational maturity in large enterprises.