Secrets detection

A collection of 73 posts

AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

Agentic AI Security: Credentials and Permissions Define the Blast Radius

* The trick matters less than the access. Three 2026 disclosures, GitLost, Claude Code's CVE-2026-21852, and Amazon Q's CVE-2026-12957, show agent manipulation determines less damage than the credentials and permissions the agent can reach. * Secrets exposure keeps

Leaked Kubernetes Secrets: Impact Assessment and Mitigation Strategies

Leaked Kubernetes Secrets: Impact Assessment and Mitigation Strategies

A single leaked Kubernetes credential rarely stays in the cluster. It opens the registry credentials, private Docker images, and private GitHub repositories behind it. In Q1 2026 alone, our detectors caught close to 2,000 new such leaks on GitHub, 28% valid at leak time.

TOP 15 Secret Scanning Tools 2026: Protect Code (but not only!) and Prevent Credential Leaks

TOP 15 Secret Scanning Tools 2026: Protect Code (but not only!) and Prevent Credential Leaks

Leaked credentials are one of the fastest paths to a breach. This guide compares the 18 best secrets detection tools for 2026 that help security teams find exposed API keys, database credentials, and hardcoded secrets before attackers do.

The Hidden Cost of Secrets Sprawl

The Hidden Cost of Secrets Sprawl

Manual secrets management costs organizations $172,000+ annually per 10 developers. Discover the hidden productivity drain, security risks, and how automation can recover at least 1.2 FTE worth of capacity.