Vault Coverage Is the Missing Metric in NHI Programs
Most vault programs track a numerator without a denominator. See how vault coverage turns secrets management into a measurable, reportable control.
Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets
A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.
40 Million Fake Push: When Spam Commits Took Over The Public GitHub
Millions of fake commits are flooding GitHub's public feed. We followed the trail to a rebranded gambling site hiding behind a defunct lottery brand.
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it.
Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines
Credential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first.
What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise
After a laptop compromise, the hard question is which credentials were on it. See why blast radius scoping is hard, and how to turn it into a revocable list.
An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker
OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.
How to Reduce Time to Revoke for Exposed Credentials
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
Why SAST and DAST Aren't Enough for Secrets Security
Static and dynamic app testing are cornerstones for any comprehensive AppSec program, yet they rarely rise up to the challenges of fully securing modern software. Discover why secrets are one of their critical blind spots.
Why identity-local signals and topology signals are two layers of the same blast radius
The credential with the widest blast radius sometimes has no secret to flag. See how GitGuardian and Anyshift rank risk by what actually breaks.
The Streak Continues: Four More Supply Chain Attacks Hit npm and PyPI
Between early June and July 14, four more supply chain attacks hit npm and PyPI: a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline. Different entry points, one target: the credentials in developer environments and build pipelines.
How to Measure Time to Revoke for Exposed Credentials
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.