<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — Secrets &amp; Credential Leaks</title>
  <link>https://appsec.fyi/secrets.html</link>
  <description>Curated Secrets &amp; Credential Leaks resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/secrets.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Wed, 22 Apr 2026 18:38:42 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours</title>
    <link>https://thehackernews.com/2026/03/unc6426-exploits-nx-npm-supply-chain.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/03/unc6426-exploits-nx-npm-supply-chain.html</guid>
    <description>UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:58 +0000</pubDate>
  </item>
  <item>
    <title>The State of Non-Human Identity Security (CSA Survey Report)</title>
    <link>https://cloudsecurityalliance.org/artifacts/state-of-non-human-identity-security-survey-report</link>
    <guid isPermaLink="true">https://cloudsecurityalliance.org/artifacts/state-of-non-human-identity-security-survey-report</guid>
    <description>The State of Non-Human Identity Security (CSA Survey Report)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:57 +0000</pubDate>
  </item>
  <item>
    <title>Secrets Management in 2026: Vault, AWS Secrets Manager, and Beyond</title>
    <link>https://www.javacodegeeks.com/2025/12/secrets-management-in-2026-vault-aws-secrets-manager-and-beyond-a-developers-guide.html</link>
    <guid isPermaLink="true">https://www.javacodegeeks.com/2025/12/secrets-management-in-2026-vault-aws-secrets-manager-and-beyond-a-developers-guide.html</guid>
    <description>Secrets Management in 2026: Vault, AWS Secrets Manager, and Beyond</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:56 +0000</pubDate>
  </item>
  <item>
    <title>GitHub Secret Scanning 2026: New Patterns, Push Protection</title>
    <link>https://www.buildmvpfast.com/blog/github-secret-scanning-pattern-updates-devops-2026</link>
    <guid isPermaLink="true">https://www.buildmvpfast.com/blog/github-secret-scanning-pattern-updates-devops-2026</guid>
    <description>GitHub Secret Scanning 2026: New Patterns, Push Protection</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:56 +0000</pubDate>
  </item>
  <item>
    <title>Top 10 Non-Human Identity Security Tools and Platforms for 2026</title>
    <link>https://blog.gitguardian.com/nhi-security-tools/</link>
    <guid isPermaLink="true">https://blog.gitguardian.com/nhi-security-tools/</guid>
    <description>Top 10 Non-Human Identity Security Tools and Platforms for 2026</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:55 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token Generation</title>
    <link>https://advisories.gitlab.com/golang/github.com/hashicorp/vault/CVE-2026-5807/</link>
    <guid isPermaLink="true">https://advisories.gitlab.com/golang/github.com/hashicorp/vault/CVE-2026-5807/</guid>
    <description>CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token Generation</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:54 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS)</title>
    <link>https://advisories.gitlab.com/golang/github.com/hashicorp/vault/CVE-2026-3605/</link>
    <guid isPermaLink="true">https://advisories.gitlab.com/golang/github.com/hashicorp/vault/CVE-2026-3605/</guid>
    <description>CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:54 +0000</pubDate>
  </item>
  <item>
    <title>AI Is Fueling Secrets Sprawl: GitGuardian Reports 81% Surge of AI-Service Leaks</title>
    <link>https://blog.gitguardian.com/the-state-of-secrets-sprawl-2026-pr/</link>
    <guid isPermaLink="true">https://blog.gitguardian.com/the-state-of-secrets-sprawl-2026-pr/</guid>
    <description>AI Is Fueling Secrets Sprawl: GitGuardian Reports 81% Surge of AI-Service Leaks</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:53 +0000</pubDate>
  </item>
  <item>
    <title>HCSEC-2026-08: Vault DoS via Unauthenticated Root Token Generation</title>
    <link>https://discuss.hashicorp.com/t/hcsec-2026-08-vault-vulnerable-to-denial-of-service-via-unauthenticated-root-token-generation-rekey-operations/77345</link>
    <guid isPermaLink="true">https://discuss.hashicorp.com/t/hcsec-2026-08-vault-vulnerable-to-denial-of-service-via-unauthenticated-root-token-generation-rekey-operations/77345</guid>
    <description>HCSEC-2026-08: Vault DoS via Unauthenticated Root Token Generation</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:52 +0000</pubDate>
  </item>
  <item>
    <title>HCSEC-2026-05: Vault KVv2 Metadata Policy Bypass DoS</title>
    <link>https://discuss.hashicorp.com/t/hcsec-2026-05-vault-kvv2-metadata-and-secret-deletion-policy-bypass-denial-of-service/77342</link>
    <guid isPermaLink="true">https://discuss.hashicorp.com/t/hcsec-2026-05-vault-kvv2-metadata-and-secret-deletion-policy-bypass-denial-of-service/77342</guid>
    <description>HCSEC-2026-05: Vault KVv2 Metadata Policy Bypass DoS</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Wed, 22 Apr 2026 12:52:51 +0000</pubDate>
  </item>
  <item>
    <title>Compromised IAM Credentials Power Large AWS Crypto Mining Campaign</title>
    <link>https://thehackernews.com/2025/12/compromised-iam-credentials-power-large.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2025/12/compromised-iam-credentials-power-large.html</guid>
    <description>Compromised IAM Credentials Power Large AWS Crypto Mining Campaign</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sun, 19 Apr 2026 02:38:42 +0000</pubDate>
  </item>
  <item>
    <title>Pre-Commit Hooks for Secret Detection: Setup in 10 Minutes</title>
    <link>https://rafter.so/blog/secrets/pre-commit-hooks-secret-detection</link>
    <guid isPermaLink="true">https://rafter.so/blog/secrets/pre-commit-hooks-secret-detection</guid>
    <description>Pre-Commit Hooks for Secret Detection: Setup in 10 Minutes</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sun, 19 Apr 2026 02:37:09 +0000</pubDate>
  </item>
  <item>
    <title>Understanding Your Organization&#x27;s Exposure to Secret Leaks — GitHub</title>
    <link>https://resources.github.com/enterprise/understanding-secret-leak-exposure/</link>
    <guid isPermaLink="true">https://resources.github.com/enterprise/understanding-secret-leak-exposure/</guid>
    <description>Understanding Your Organization&#x27;s Exposure to Secret Leaks — GitHub</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sun, 19 Apr 2026 02:22:23 +0000</pubDate>
  </item>
  <item>
    <title>Exposed Developer Secrets Surge: AI Drives 34% Increase in 2025</title>
    <link>https://securityledger.com/2026/03/exposed-developer-secrets-surge-ai-drives-34-increase-in-2025/</link>
    <guid isPermaLink="true">https://securityledger.com/2026/03/exposed-developer-secrets-surge-ai-drives-34-increase-in-2025/</guid>
    <description>Exposed Developer Secrets Surge: AI Drives 34% Increase in 2025</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sun, 19 Apr 2026 02:22:23 +0000</pubDate>
  </item>
  <item>
    <title>GitHub Found 39M Secret Leaks in 2024 — The GitHub Blog</title>
    <link>https://github.blog/security/application-security/next-evolution-github-advanced-security/</link>
    <guid isPermaLink="true">https://github.blog/security/application-security/next-evolution-github-advanced-security/</guid>
    <description>GitHub Found 39M Secret Leaks in 2024 — The GitHub Blog</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sun, 19 Apr 2026 02:22:22 +0000</pubDate>
  </item>
  <item>
    <title>Non-human identities: What they are and how to secure them (Netwrix)</title>
    <link>https://netwrix.com/en/resources/blog/non-human-identities/</link>
    <guid isPermaLink="true">https://netwrix.com/en/resources/blog/non-human-identities/</guid>
    <description>Non-human identities: What they are and how to secure them (Netwrix)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:40 +0000</pubDate>
  </item>
  <item>
    <title>Top non-human identity (NHI) platforms of 2025 (Doppler)</title>
    <link>https://www.doppler.com/blog/top-nhi-platforms-2025-secrets-machine-identity</link>
    <guid isPermaLink="true">https://www.doppler.com/blog/top-nhi-platforms-2025-secrets-machine-identity</guid>
    <description>Top non-human identity (NHI) platforms of 2025 (Doppler)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:39 +0000</pubDate>
  </item>
  <item>
    <title>What Are Non-Human Identities? Complete NHI Security Guide 2025</title>
    <link>https://permiso.io/non-human-identity-nhi-security-guide</link>
    <guid isPermaLink="true">https://permiso.io/non-human-identity-nhi-security-guide</guid>
    <description>What Are Non-Human Identities? Complete NHI Security Guide 2025</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:38 +0000</pubDate>
  </item>
  <item>
    <title>TruffleHog: Deep Dive on Secret Management (Jit)</title>
    <link>https://www.jit.io/resources/appsec-tools/trufflehog-a-deep-dive-on-secret-management-and-how-to-fix-exposed-secrets</link>
    <guid isPermaLink="true">https://www.jit.io/resources/appsec-tools/trufflehog-a-deep-dive-on-secret-management-and-how-to-fix-exposed-secrets</guid>
    <description>TruffleHog: Deep Dive on Secret Management (Jit)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:08 +0000</pubDate>
  </item>
  <item>
    <title>TruffleHog Open Source v3 vs GitGuardian</title>
    <link>https://www.gitguardian.com/comparisons/trufflehog-v3</link>
    <guid isPermaLink="true">https://www.gitguardian.com/comparisons/trufflehog-v3</guid>
    <description>TruffleHog Open Source v3 vs GitGuardian</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:07 +0000</pubDate>
  </item>
  <item>
    <title>git-secret-scanner: Find secrets with TruffleHog &amp; Gitleaks</title>
    <link>https://github.com/padok-team/git-secret-scanner</link>
    <guid isPermaLink="true">https://github.com/padok-team/git-secret-scanner</guid>
    <description>git-secret-scanner: Find secrets with TruffleHog &amp; Gitleaks</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:06 +0000</pubDate>
  </item>
  <item>
    <title>Gitleaks vs TruffleHog 2026 Benchmarks (AppSec Santa)</title>
    <link>https://appsecsanta.com/sast-tools/gitleaks-vs-trufflehog</link>
    <guid isPermaLink="true">https://appsecsanta.com/sast-tools/gitleaks-vs-trufflehog</guid>
    <description>Gitleaks vs TruffleHog 2026 Benchmarks (AppSec Santa)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:06 +0000</pubDate>
  </item>
  <item>
    <title>Rafter: detect-secrets vs gitleaks vs TruffleHog</title>
    <link>https://rafter.so/blog/secrets/secret-scanning-tools-comparison</link>
    <guid isPermaLink="true">https://rafter.so/blog/secrets/secret-scanning-tools-comparison</guid>
    <description>Rafter: detect-secrets vs gitleaks vs TruffleHog</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:05 +0000</pubDate>
  </item>
  <item>
    <title>SEC02-BP03 Store and use secrets securely (AWS Well-Architected)</title>
    <link>https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_secrets.html</link>
    <guid isPermaLink="true">https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_secrets.html</guid>
    <description>SEC02-BP03 Store and use secrets securely (AWS Well-Architected)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:04 +0000</pubDate>
  </item>
  <item>
    <title>AWS Secrets Manager: Secure Credential Storage &amp; Best Practices</title>
    <link>https://sedai.io/blog/manage-secrets-aws-secrets-manager</link>
    <guid isPermaLink="true">https://sedai.io/blog/manage-secrets-aws-secrets-manager</guid>
    <description>AWS Secrets Manager: Secure Credential Storage &amp; Best Practices</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:03 +0000</pubDate>
  </item>
  <item>
    <title>Practical steps to minimize key exposure using AWS Security (AWS)</title>
    <link>https://aws.amazon.com/blogs/security/practical-steps-to-minimize-key-exposure-using-aws-security-services/</link>
    <guid isPermaLink="true">https://aws.amazon.com/blogs/security/practical-steps-to-minimize-key-exposure-using-aws-security-services/</guid>
    <description>Practical steps to minimize key exposure using AWS Security (AWS)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:03 +0000</pubDate>
  </item>
  <item>
    <title>AWS API Keys / Secrets / Tokens Exposure Remediation</title>
    <link>https://www.dspmguides.com/guides/fix-exposure-of-api-keys-secrets-tokens-aws/</link>
    <guid isPermaLink="true">https://www.dspmguides.com/guides/fix-exposure-of-api-keys-secrets-tokens-aws/</guid>
    <description>AWS API Keys / Secrets / Tokens Exposure Remediation</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:02 +0000</pubDate>
  </item>
  <item>
    <title>Integrating HashiCorp Vault with Kubernetes for Secrets Mgmt</title>
    <link>https://dev.to/mark_mwendia_0298dd9c0aad/integrating-hashicorp-vault-with-kubernetes-for-secure-secrets-management-1gn9</link>
    <guid isPermaLink="true">https://dev.to/mark_mwendia_0298dd9c0aad/integrating-hashicorp-vault-with-kubernetes-for-secure-secrets-management-1gn9</guid>
    <description>Integrating HashiCorp Vault with Kubernetes for Secrets Mgmt</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:01 +0000</pubDate>
  </item>
  <item>
    <title>HashiCorp Vault Kubernetes: The Definitive Guide (Plural)</title>
    <link>https://www.plural.sh/blog/hashicorp-vault-kubernetes-guide/</link>
    <guid isPermaLink="true">https://www.plural.sh/blog/hashicorp-vault-kubernetes-guide/</guid>
    <description>HashiCorp Vault Kubernetes: The Definitive Guide (Plural)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:45:00 +0000</pubDate>
  </item>
  <item>
    <title>A Hands-On Guide to Vault in Kubernetes</title>
    <link>https://medium.com/@muppedaanvesh/a-hand-on-guide-to-vault-in-kubernetes-%EF%B8%8F-1daf73f331bd</link>
    <guid isPermaLink="true">https://medium.com/@muppedaanvesh/a-hand-on-guide-to-vault-in-kubernetes-%EF%B8%8F-1daf73f331bd</guid>
    <description>A Hands-On Guide to Vault in Kubernetes</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:59 +0000</pubDate>
  </item>
  <item>
    <title>Securing Kubernetes Secrets with HashiCorp Vault (InfraCloud)</title>
    <link>https://www.infracloud.io/blogs/kubernetes-secrets-hashicorp-vault/</link>
    <guid isPermaLink="true">https://www.infracloud.io/blogs/kubernetes-secrets-hashicorp-vault/</guid>
    <description>Securing Kubernetes Secrets with HashiCorp Vault (InfraCloud)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:59 +0000</pubDate>
  </item>
  <item>
    <title>Manage Kubernetes native secrets with Vault Secrets Operator</title>
    <link>https://developer.hashicorp.com/vault/tutorials/kubernetes-introduction/vault-secrets-operator</link>
    <guid isPermaLink="true">https://developer.hashicorp.com/vault/tutorials/kubernetes-introduction/vault-secrets-operator</guid>
    <description>Manage Kubernetes native secrets with Vault Secrets Operator</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:58 +0000</pubDate>
  </item>
  <item>
    <title>Secret detection (GitLab Docs)</title>
    <link>https://docs.gitlab.com/user/application_security/secret_detection/</link>
    <guid isPermaLink="true">https://docs.gitlab.com/user/application_security/secret_detection/</guid>
    <description>Secret detection (GitLab Docs)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:57 +0000</pubDate>
  </item>
  <item>
    <title>Find secrets with GitHub secret risk assessment</title>
    <link>https://github.blog/changelog/2025-03-04-find-secrets-in-your-organization-with-the-secret-risk-assessment/</link>
    <guid isPermaLink="true">https://github.blog/changelog/2025-03-04-find-secrets-in-your-organization-with-the-secret-risk-assessment/</guid>
    <description>Find secrets with GitHub secret risk assessment</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:56 +0000</pubDate>
  </item>
  <item>
    <title>About secret scanning (GitHub Docs)</title>
    <link>https://docs.github.com/code-security/secret-scanning/about-secret-scanning</link>
    <guid isPermaLink="true">https://docs.github.com/code-security/secret-scanning/about-secret-scanning</guid>
    <description>About secret scanning (GitHub Docs)</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Fri, 17 Apr 2026 14:44:56 +0000</pubDate>
  </item>
  <item>
    <title>Do Not Use Secrets in Environment Variables</title>
    <link>https://www.nodejs-security.com/blog/do-not-use-secrets-in-environment-variables-and-here-is-how-to-do-it-better</link>
    <guid isPermaLink="true">https://www.nodejs-security.com/blog/do-not-use-secrets-in-environment-variables-and-here-is-how-to-do-it-better</guid>
    <description>Do Not Use Secrets in Environment Variables</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:38 +0000</pubDate>
  </item>
  <item>
    <title>Environment Variables Don&#x27;t Keep Secrets</title>
    <link>https://developer.cyberark.com/blog/environment-variables-dont-keep-secrets-best-practices-for-plugging-application-credential-leaks/</link>
    <guid isPermaLink="true">https://developer.cyberark.com/blog/environment-variables-dont-keep-secrets-best-practices-for-plugging-application-credential-leaks/</guid>
    <description>Environment Variables Don&#x27;t Keep Secrets</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:37 +0000</pubDate>
  </item>
  <item>
    <title>From .env to Leakage: Mishandling of Secrets by Coding Agents</title>
    <link>https://www.knostic.ai/blog/claude-cursor-env-file-secret-leakage</link>
    <guid isPermaLink="true">https://www.knostic.ai/blog/claude-cursor-env-file-secret-leakage</guid>
    <description>From .env to Leakage: Mishandling of Secrets by Coding Agents</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:36 +0000</pubDate>
  </item>
  <item>
    <title>Secret Detection in Application Security</title>
    <link>https://apiiro.com/blog/secret-detection-in-application-security/</link>
    <guid isPermaLink="true">https://apiiro.com/blog/secret-detection-in-application-security/</guid>
    <description>Secret Detection in Application Security</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:36 +0000</pubDate>
  </item>
  <item>
    <title>29 Million Leaked Secrets: How AI Coding Tools Are Making It Worse</title>
    <link>https://www.helpnetsecurity.com/2026/04/14/gitguardian-ai-agents-credentials-leak/</link>
    <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/04/14/gitguardian-ai-agents-credentials-leak/</guid>
    <description>29 Million Leaked Secrets: How AI Coding Tools Are Making It Worse</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:35 +0000</pubDate>
  </item>
  <item>
    <title>The State of Secrets Sprawl 2026 - GitGuardian Annual Report</title>
    <link>https://www.gitguardian.com/state-of-secrets-sprawl-report-2026</link>
    <guid isPermaLink="true">https://www.gitguardian.com/state-of-secrets-sprawl-report-2026</guid>
    <description>The State of Secrets Sprawl 2026 - GitGuardian Annual Report</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Thu, 16 Apr 2026 21:04:34 +0000</pubDate>
  </item>
  <item>
    <title>Terraform Secrets Management Best Practices</title>
    <link>https://blog.gitguardian.com/terraform-secrets-management/</link>
    <guid isPermaLink="true">https://blog.gitguardian.com/terraform-secrets-management/</guid>
    <description>Terraform Secrets Management Best Practices</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:43 +0000</pubDate>
  </item>
  <item>
    <title>AWS IAM Roles Anywhere Workload Identities</title>
    <link>https://docs.aws.amazon.com/rolesanywhere/latest/userguide/workload-identities.html</link>
    <guid isPermaLink="true">https://docs.aws.amazon.com/rolesanywhere/latest/userguide/workload-identities.html</guid>
    <description>AWS IAM Roles Anywhere Workload Identities</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:42 +0000</pubDate>
  </item>
  <item>
    <title>External Secrets Operator: Introduction</title>
    <link>https://external-secrets.io/</link>
    <guid isPermaLink="true">https://external-secrets.io/</guid>
    <description>External Secrets Operator: Introduction</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:42 +0000</pubDate>
  </item>
  <item>
    <title>Google Cloud SIEM Service Account Token Leak</title>
    <link>https://www.tenable.com/security/research/tra-2025-52</link>
    <guid isPermaLink="true">https://www.tenable.com/security/research/tra-2025-52</guid>
    <description>Google Cloud SIEM Service Account Token Leak</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:41 +0000</pubDate>
  </item>
  <item>
    <title>Secret Rotation: How It Works</title>
    <link>https://www.groundcover.com/learn/security/secret-rotation-how-it-works-challenges-best-practices</link>
    <guid isPermaLink="true">https://www.groundcover.com/learn/security/secret-rotation-how-it-works-challenges-best-practices</guid>
    <description>Secret Rotation: How It Works</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:40 +0000</pubDate>
  </item>
  <item>
    <title>Secret Auto Rotation with Secrets Store CSI Driver</title>
    <link>https://secrets-store-csi-driver.sigs.k8s.io/topics/secret-auto-rotation</link>
    <guid isPermaLink="true">https://secrets-store-csi-driver.sigs.k8s.io/topics/secret-auto-rotation</guid>
    <description>Secret Auto Rotation with Secrets Store CSI Driver</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:39 +0000</pubDate>
  </item>
  <item>
    <title>Secretless GitHub Actions to AWS via OIDC</title>
    <link>https://www.codecentric.de/en/knowledge-hub/blog/secretless-connections-from-github-actions-to-aws-using-oidc</link>
    <guid isPermaLink="true">https://www.codecentric.de/en/knowledge-hub/blog/secretless-connections-from-github-actions-to-aws-using-oidc</guid>
    <description>Secretless GitHub Actions to AWS via OIDC</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:38 +0000</pubDate>
  </item>
  <item>
    <title>OIDC Security Hardening for GitHub Actions</title>
    <link>https://docs.github.com/en/actions/concepts/security/openid-connect</link>
    <guid isPermaLink="true">https://docs.github.com/en/actions/concepts/security/openid-connect</guid>
    <description>OIDC Security Hardening for GitHub Actions</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:37 +0000</pubDate>
  </item>
  <item>
    <title>Hardening HashiCorp Vault Best Practices</title>
    <link>https://sjramblings.io/secure-your-secrets-best-practices-for-hardening-hashicorp-vault-in-production/</link>
    <guid isPermaLink="true">https://sjramblings.io/secure-your-secrets-best-practices-for-hardening-hashicorp-vault-in-production/</guid>
    <description>Hardening HashiCorp Vault Best Practices</description>
    <category>Secrets &amp; Credential Leaks</category>
    <pubDate>Sat, 11 Apr 2026 16:48:37 +0000</pubDate>
  </item>
</channel>
</rss>