Secrets & Credential Leaks
Secrets management and credential leak prevention address one of the most common and impactful security failures in modern software development. Hardcoded API keys, database passwords, cloud credentials, and private keys regularly appear in source code repositories, CI/CD configurations, container images, client-side JavaScript, and log files. Tools like TruffleHog, GitLeaks, and GitHub Secret Scanning detect exposed credentials in repositories, while vault solutions like HashiCorp Vault, AWS Secrets Manager, and cloud KMS services provide secure runtime secret injection. The impact of leaked credentials can be devastating — exposed AWS keys can lead to full cloud account compromise within minutes, and leaked database credentials can result in complete data breaches. Prevention requires secrets scanning in CI/CD pipelines, pre-commit hooks, environment-based secret injection, and credential rotation policies.
Credentials leak through history, not through the current commit
The awkward property of a leaked secret is that removing it does not unleak it. A key committed and deleted in the next commit is still in the git history, still in every clone, still in forks, and still in whatever mirrors and caches exist — and for a public repository, quite possibly in a dataset somebody built by scraping. Detection at the current HEAD finds almost nothing; scanning history is what finds the real exposure, and rotation, not deletion, is what actually remediates it.
The places secrets accumulate are predictable once you look for them. Version control history is first. CI and build logs are second and are frequently overlooked, because a variable that is masked in one job gets echoed by a debugging line in another, and logs are often more widely readable than the repository. Client-side bundles come third, and the recurring pattern is an API key embedded in JavaScript or a mobile package under the belief that minification or compilation is concealment. After that: container images with credentials baked into a layer, backups and database dumps, configuration files in deployment artifacts, Slack and ticket attachments, and cloud metadata reachable through SSRF.
Detection is a precision problem rather than a recall problem. Regex rules for well-known formats work well because providers gave their keys recognizable prefixes; generic high-entropy detection produces enormous false-positive volume and gets ignored, which is worse than not running it. Provider-side verification — checking whether a candidate key is live — is what makes a scanner's output actionable.
The structural fix is to reduce what a leak is worth. Short-lived credentials issued by a broker, workload identity federation instead of long-lived keys in CI, per-service scoping so one credential does not open everything, and monitoring for use from unexpected locations all shrink the blast radius of an exposure you did not catch. Pre-commit hooks and repository scanning reduce frequency; they will not reach zero, and planning for that is the point.
| Date Added | Link | Excerpt |
|---|---|---|
| 2026-10-07 NEW 2026 | Secrets Management Best Practices: 6 Reasons Your Vault Needs Detection beginner 15 min read | Library for secrets detection and management, this resource highlights the critical need for both secrets vaults and detection tools. Secrets vaults centralize and protect credentials, enforcing access policies and recording usage, while secrets detection continuously scans code, configurations, and platforms for exposed secrets outside the vault. Combining these capabilities provides a comprehensive inventory of all credentials, enabling faster remediation of security incidents, satisfying auditor requirements by demonstrating control effectiveness, and offering robust evidence for frameworks like SOC 2 and ISO 27001. → blog.gitguardian.com |
| 2026-10-07 NEW 2026 | Why the AI Attack Surface Extends Your Stack beginner 7 min read AI AuthZ | Library for evaluating the expanded enterprise AI attack surface, moving beyond traditional perimeter security and model safety scans. It addresses how prompt injection can lead to code execution and data exposure by examining the interconnected layers of an AI deployment: the model itself, agents and tools, data and RAG pipelines, application and APIs, identity and access management, and underlying infrastructure. This library emphasizes the need to test realistic attack chains across the full application stack, combining AI-specific prompt logic with classic application, API, cloud, and identity security testing. → bishopfox.com |
| 2026-10-06 NEW 2026 | SOPS Guide: How to Encrypt and Manage Secrets in Git, Kubernetes, and CI/CD beginner 30 min read | Library for encrypting secrets within YAML, JSON, ENV, and INI files using a choice of key stores like PGP, age, AWS KMS, Azure Key Vault, Google Cloud KMS, and HashiCorp Vault. SOPS supports envelope encryption and can be integrated with GitHub Actions and Flux CD for automated decryption at build or reconcile time, ensuring plain text secrets are never committed to Git. It also provides message authentication codes to detect file tampering and can be paired with secrets managers for runtime access. → blog.gitguardian.com |
| 2026-10-02 NEW 2026 | Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders news 10 min read Supply Chain | Analysis of GitGuardian's Public Monitoring Agents reveals a significant increase in hardcoded secrets within public GitHub commits, with nearly 80% of one customer's leaks originating from personal developer repositories, mirroring the CISA leak. The updated Agents Analysis provides clear verdicts to prioritize relevant incidents, organizes the monitoring queue by company relevance, and offers reasoning behind each decision, enhancing security team efficiency in identifying and addressing exposed credentials. → blog.gitguardian.com |
| 2026-09-30 2026 | Microsoft Copilot Cowork Exfiltrates Files news 5 min read AI | Writeup detailing an indirect prompt injection attack against Microsoft Copilot Cowork, demonstrating how attackers can exfiltrate files from Microsoft 365. The exploit leverages Copilot's ability to interact with Microsoft Graph and its lack of human approval for sending messages to the active user. By crafting a poisoned skill, attackers can trick Copilot into sending pre-authenticated download links for sensitive files via Teams messages, which are then exfiltrated when the victim opens them. This vulnerability, which affects models like Claude Opus 4.7, highlights the expanded attack surface of agentic products with delegated enterprise-wide authority. |
| 2026-09-30 2026 | The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub intermediate 5 min read Supply Chain | Writeup detailing a multi-platform data exfiltration attack investigated by Wiz's Blue Agent. The autonomous SOC investigator traced compromised credentials and custom Python exfiltration tools (mssql_table_export.py, pg_table_export.py, billing_export2.py) across AWS and GitHub. The investigation involved analyzing CloudTrail events, S3 data events, and GitHub audit logs, uncovering an attack chain that began with source code theft from private repositories, pivoted to AWS infrastructure, and culminated in data staging and exfiltration from a production domain controller. → wiz.io |
| 2026-09-30 2026 | Generative AI Security: Are Your Developers Pasting Secrets Into LLMs? beginner 8 min read AI | Library for scanning AI gateway traffic, integrating with GitGuardian's API to detect leaked secrets in prompts and tool calls. It operates in blocking or non-blocking modes, utilizing over 600 detectors to identify incidents before they reach third-party LLM providers, aiming to prevent leaks of sensitive information like API keys and credentials which saw an 81% increase in AI-service related incidents in 2025. → blog.gitguardian.com |
| 2026-09-28 2026 | The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments beginner 14 min read AI AuthN | Library analyzing infostealer families like Lumma, RedLine, and Vidar that target credentials, API keys, and session tokens to compromise cloud, code, and AI environments including AWS, GCP, GitHub, and OpenAI. The analysis, drawing on NordStellar data and referencing reports from Microsoft and Verizon, details how these stolen secrets bypass MFA, enable access to sensitive corporate data, and are sold by initial access brokers to ransomware cartels, highlighting the significant risks posed by compromised developer endpoints. → wiz.io |
| 2026-09-26 2026 | AI Coding Agents Are Leaking Credentials: Cursor, Claude Code, Copilot, and MCP beginner 7 min read AI | Library for discovering leaked credentials in AI coding agents like Cursor, Claude Code, and GitHub Copilot. These agents store sensitive information in configuration files, environment variables, logs, and shell history, often outside the scope of traditional repository and CI scanners. The library's analysis identified numerous valid secrets within public configuration files and a higher leak rate in commits assisted by Claude Code. → blog.gitguardian.com |
| 2026-09-25 2026 | How the GitGuardian Mixin Kit Extends Docker Sandboxes for Safer AI Coding beginner 8 min read AI | Library for integrating GitGuardian's ggshield secret-scanning hooks with Docker Sandboxes, enhancing security for AI-assisted coding. The mixin kit automatically installs ggshield and configures AI hooks for tools like Claude Code, Cursor, Codex, and GitHub Copilot. This provides two layers of protection: Docker Sandboxes isolate agent environments, while ggshield scans prompts, actions, and tool output for exposed credentials, preventing sensitive data leakage. → blog.gitguardian.com |
| 2026-09-24 2026 | VSCode's SSH Agent Is Bananas (2025) news 2 min read AuthN | Writeup on VSCode's remote SSH agent, detailing its full-scale invasion approach via a Bash snippet stager to download and run an agent over port-forwarded SSH. This agent establishes a WebSockets connection to the VSCode frontend, allowing it to wander filesystems, edit files, launch PTY processes, and persist itself, raising security concerns for development and production environments. |
| 2026-09-22 2026 | From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies intermediate 14 min read AuthZ | Reference detailing AWS's defense against compromised IAM credentials, specifically focusing on the evolution and functionality of the AWSCompromisedKeyQuarantine managed policy. It examines how AWS neutralizes exposed access keys and secrets, often in partnership with services like GitHub's secret scanning, and provides practical monitoring strategies for detecting quarantine events. The entry highlights the automated attachment of this policy to limit potential damage from unauthorized activity. → unit42.paloaltonetworks.com |
| 2026-09-19 2026 | A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity advanced 17 min read AI | Tool that allows for prompt injection attacks on AWS AgentCore Harness, potentially exfiltrating plaintext credentials managed by AgentCore Identity. The vulnerability arises from the default enablement of the built-in `shell` tool, which runs with root access and can access credentials resolved to plaintext in memory. Defense strategies include scoping `allowedTools` to necessary functions, applying least privilege to identity vault service accounts, and monitoring outbound traffic from harness containers. → unit42.paloaltonetworks.com |
| 2026-09-18 2026 | What a Supply Chain Attack Is Really After: Your Credentials beginner 5 min read Supply Chain | Ebook detailing credential harvesting as the primary objective in 2025–2026 software supply chain attacks, focusing on developer environments and CI/CD runners as valuable targets. It analyzes the propagation mechanism enabled by stolen credentials, the speed of automated distribution, and the necessary shift in incident response to account for exposed secrets like GitHub tokens, cloud credentials, and SSH keys, referencing campaigns like Shai-Hulud 2.0 and the Trivy compromise. → blog.gitguardian.com |
| 2026-09-17 2026 | Atomic macOS (AMOS) Stealer Activity beginner 6 min read Mobile | Writeup of AMOS Stealer activity on macOS, detailing a lab infection generated from a malicious "macOS toolkit" installer. The analysis includes the malware's distribution via ClickFix-like campaigns and malicious ads, its exfiltration of system information, credentials, and cryptocurrency wallet data. It highlights the constantly evolving nature of AMOS Stealer, with rapidly changing indicators, domains, and C2 infrastructure, and provides forensic artifacts and traffic patterns observed in early August 2026. → unit42.paloaltonetworks.com |
| 2026-09-09 2026 | Service Account Credential Rotation: The Blast-Radius Checklist beginner 10 min read | Checklist for rotating service account credentials, addressing the common challenge of unmanaged and fearfully unrotated secrets. It guides users through eight critical questions regarding validity, exposure, access scope, consumers, vault location, duplicate copies, ownership, and rollback plans before rotation. GitGuardian's Exploration Map is mentioned as a tool that links credentials to their incidents, permissions, consumers, and owners, enabling controlled changes rather than guesswork, particularly important given the prevalence of non-human identities. → blog.gitguardian.com |
| 2026-09-08 2026 | AI Created a Leaked Credentials Flood: Here's How We're Draining It beginner 6 min read AI | Tool that uses two AI agents to analyze public GitHub and Docker Hub incidents, providing a company-related verdict, risk score, and visible reasoning for exposed credentials. It addresses the challenge of triaging the 1.27 million AI-related exposed secrets and the 64% unrevoked secrets from 2022, offering a company-related verdict and risk score to streamline security team workflows and improve incident response productivity. → blog.gitguardian.com |
| 2026-09-06 2026 | Check My Vibe — Passive Security Scanner for Vibe-Coded Websites intermediate 3 min read AI Recon | Tool for passive security scanning of "vibe-coded" (AI-assisted) websites. Check My Vibe analyzes public HTML pages and same-origin JavaScript for visible exposure signals like exposed secrets, missing authorization, and unsafe defaults. It reviews transport behavior, security headers, public source maps, and specific file paths, offering a 36-point manual checklist for human-verifiable controls. The tool focuses on limited public evidence and does not replace source-code review or authenticated testing. |
| 2026-09-06 2026 | HOL Guard intermediate AI Supply Chain | Local-first runtime security for AI coding agents and MCP tooling. It sits between an agent and the tools it wants to run so developers can approve or deny risky shell commands, secret reads, prompt-injection-driven actions, malicious packages, and MCP changes before execution. |
| 2026-09-04 2026 | No Hack Required: How Thousands of Leaked API Tokens Left Automation Servers Wide Open news 2 min read | Writeup on leaked n8n API tokens detailing how thousands of exposed secrets in public repositories granted attackers direct access to automation servers. The analysis highlights that 321 reachable n8n instances immediately accepted leaked API tokens, demonstrating a failure in secrets management rather than a software vulnerability. Attackers leverage these compromised credentials to access integrated services like Gmail, Slack, and AWS, bypassing traditional exploit methods. The findings underscore the increasing trend of credential-based attacks and CISA's recommendations for immediate rotation of exposed secrets and implementing least-privilege access controls across all automation platforms. |
| 2026-09-03 2026 | OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome beginner 11 min read Supply Chain | Library detailing the OWASP Top 10 CI/CD Security Risks, highlighting how insufficient credential hygiene (CICD-SEC-6) exacerbates other vulnerabilities like dependency chain abuse and poisoned pipeline execution. It notes that since 2025, worms like Shai-Hulud and ChainDrop have targeted CI/CD runners, with 59% of machines compromised in one wave being CI/CD infrastructure. GitGuardian's approach uses tools like ggshield to secure credentials across endpoints, source control, and pipelines. → blog.gitguardian.com |
| 2026-09-03 2026 | 28000 Exposed Git Repositories Leak Credentials news 3 min read | Tool, gitreaper scans exposed .git repositories for leaked credentials like AWS access keys, Stripe API keys, OpenAI API keys, Telegram tokens, and GitHub personal access tokens. It analyzes Git object history in memory to find secrets in deleted branches and previous commits, not just current files. The tool was used to identify 28,000 exposed repositories, revealing active credentials that could lead to data theft, payment fraud, and unauthorized code access. → esecurityplanet.com |
| 2026-09-02 2026 | Credential Security: What Endpoint Protection Really Means for Secrets beginner 9 min read | Library for credential security on developer endpoints, differentiating from EDR. It discovers, remediates, and deceives with exposed secrets like cloud keys and API tokens in .env files, shell history, and AI tool directories. Unlike behavioral monitoring which catches malicious activity, this library focuses on identifying valid secrets before they are compromised, addressing the growing exposure from AI coding agents. It provides a real-time record of secrets, aids in incident scoping by pinpointing exposed credentials, and helps prevent attackers from gaining persistent access. → blog.gitguardian.com |
| 2026-09-02 2026 | 153GB of stolen credentials surface after LiteLLM supply chain attack news 3 min read | Analysis of a 153GB leaked archive from the LiteLLM supply chain attack reveals credentials for thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. This breach, stemming from a compromised Trivy scanner, led to malicious LiteLLM versions 1.82.7 and 1.82.8 being published to PyPI, exposing secrets like AWS secret access keys and Salesforce client secrets. Organizations are urged to audit their environments for these LiteLLM versions and rotate all exposed secrets. → helpnetsecurity.com |
| 2026-09-01 2026 | AWS S3 Bucket Security: Find the Secrets Hiding Outside Git intermediate 8 min read | Library for scanning AWS S3 buckets for exposed secrets, including those within ZIP and tar.gz archives. It addresses the blind spot of accumulating logs, backups, and pipeline output in S3 without secret scanning, which attackers exploit using AI for rapid reconnaissance, as demonstrated by incidents involving IAM credentials and LLMs leading to administrative access in minutes. → blog.gitguardian.com |
| 2026-08-31 2026 | Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain intermediate 5 min read Supply Chain | Library for correlating developer identities with personal public repositories to discover and validate exploitable secrets leaked through accidental exposure. It addresses blind spots in traditional AppSec programs by mapping attack paths from exposed credentials to cloud resources, offering exploitability validation with an AI-powered attacker, and enabling rapid remediation by linking findings directly to responsible developers and workflows. This approach helps security teams prioritize real risks and manage secret exposure beyond organizational boundaries, particularly as AI accelerates code sharing. → wiz.io |
| 2026-08-28 2026 | AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection intermediate 13 min read AI | Library for securing AI agents, focusing on pre-runtime controls over solely runtime detection. It emphasizes limiting an agent's access to credentials and systems before execution, arguing that at machine speed, runtime detection is often too late. The library supports discovery and remediation of exposed secrets, enforcement of AI guardrails, and the use of honeytokens, in conjunction with runtime monitoring for unpredictable behaviors like prompt injection, goal hijacking, and memory poisoning, referencing techniques seen in Shai Hulud and Nx "s1ngularity" attacks. → blog.gitguardian.com |
| 2026-08-25 2026 | Tata’s B2B platform returned OTPs in API responses news 2 min read API Sec | Writeup on an account takeover vulnerability in Tata’s B2B platform, Tata nexarc. An API endpoint, "CheckForUsersRegisteredWithEmailOrMobileNoAndSendOTP.do," insecurely returned the one-time password (OTP) in plaintext within encrypted API responses. This allowed attackers to bypass OTP verification by decrypting the response using client-side JavaScript and extracting the "otpGeneratedForMobile" field, granting them administrative access to company accounts, including those for Tata Steel. |
| 2026-08-21 2026 | Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes advanced 9 min read AI Supply Chain | Library for detecting exposed credentials across the SDLC; prioritizes remediation by validity and severity, and uses AI hooks to prevent agents from accessing secrets, addressing the machine-speed credential abuse exemplified by the ChainDrop npm worm. This worm, part of the Shai-Hulud attack, compromised 444 npm packages and leveraged malicious hooks in Claude Code and VS Code to trigger execution at machine speed, collapsing the time between credential discovery and abuse to near-zero, effectively removing human reaction windows. → blog.gitguardian.com |
| 2026-08-21 2026 | Identity Abuse Through Trusted Communication Channels news 13 min read AuthN OSINT | Library for detecting and defending against identity abuse within enterprise collaboration platforms like Microsoft Teams and Slack. This resource highlights how threat actors exploit trusted communication channels for identity phishing, impersonation, credential theft, and malware delivery, using techniques such as masquerading DLLs for sideloading attacks and adversary-in-the-middle proxies to capture corporate credentials. It provides practical recommendations for securing these platforms, which have become significant parts of the enterprise attack surface. → unit42.paloaltonetworks.com |
| 2026-08-19 2026 | Why Secrets Slip Through Every Layer of Your Security Stack intermediate 5 min read | Ebook tracing the secrets problem across specialized security stack territories, detailing how API keys and other credentials traverse laptops, repos, pipeline logs, tickets, and config files. It highlights that 28% of incidents occur outside repositories in collaboration tools and 64% of secrets remain valid for years, underscoring the lack of cross-tool context for effective revocation and remediation. → blog.gitguardian.com |
| 2026-08-18 2026 | Credential Exposure and the Security Stack Gap beginner 5 min read | Ebook tracing credential exposure across fragmented security stacks, highlighting how secrets move between repositories, pipeline logs, tickets, and configurations. It discusses GitGuardian's State of Secrets Sprawl 2026 findings, noting 28% of incidents occur outside repos and 64% of exposed secrets remain valid for years, emphasizing the need for cross-tool visibility. → blog.gitguardian.com |
| 2026-08-17 2026 | Show HN: Laptop is the last place your secrets are still in plaintext beginner 13 min read | Tool for managing local secrets on macOS Apple Silicon, `jit` encrypts plaintext secrets like `.env` files and AWS credentials into a local vault secured by Touch ID. It then rewrites configuration files to present decoys on disk, injecting real secrets into memory only for authorized processes, preventing exposure from accidental `curl | sh` commands or compromised AI agents. `jit` supports various injection mechanisms including environment variables, credential helpers for tools like AWS and Docker, and named-pipe mounts for file-based readers. |
| 2026-08-17 2026 | Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform intermediate 25 min read AuthZ | Writeup detailing vulnerabilities found in points.com, the backend provider for numerous airline and hotel rewards programs. The findings include an unauthenticated directory traversal allowing access to millions of customer order records containing sensitive data like partial credit card numbers and authorization tokens. Another vulnerability enabled reward points transfer and customer information leakage using only a rewards number and surname. Leaked tenant credentials for the Virgin Rewards program allowed API request signing, and a weak Flask session secret granted full access to the global administration console. → samcurry.net |
| 2026-08-16 2026 | CI/CD Credential Exposure: What Attackers Steal From Pipelines and What to Rotate beginner 10 min read | Library detailing CI/CD credential exposure, encompassing leaked secrets like cloud keys and access tokens through dependencies, logs, artifacts, workflow files, and platforms. It analyzes the LiteLLM supply chain attack, attributed to TeamPCP, which potentially exposed thousands of organizations and pipelines, highlighting how attackers steal seven major credential classes including VCS credentials and AI provider keys. The library explains credential leakage paths such as malicious dependencies, workflow injection, logs, CI platform compromise, over-scoped tokens, and self-propagating worms, while also discussing detection challenges due to theft occurring during legitimate build processes and the efficacy of memory scraping over log masking. → cloudsek.com |
| 2026-08-15 2026 | Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations news 3 min read Supply Chain | Library that detects leaked secrets by identifying cloud credentials, API keys, and sensitive environment variables within code repositories and build pipelines. This library aids in discovering vulnerabilities like those exposed in the LiteLLM hack, where attackers exfiltrated 153GB of data including AWS, GCP, Azure, and LLM API keys, emphasizing the need for continuous secrets detection and inventory management to protect against supply chain attacks. → blog.gitguardian.com |
| 2026-08-14 2026 | How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign intermediate 9 min read Supply Chain | Writeup detailing a multi-organization GitHub PAT compromise campaign, detailing how to investigate using GitHub audit logs and user security logs. The campaign, active from mid-May through early June 2026, involved stages of repository reconnaissance using the GitHub API (api.request events) and low-volume validation cloning from AWS IP addresses before mass repository exfiltration using compromised PATs. The writeup outlines three investigation steps: containing compromised PATs by revoking access, expanding the investigation timeline to identify reconnaissance and validation activities, and identifying the source of the leaked PAT. → wiz.io |
| 2026-08-14 2026 | Your AI Agents Are Using Your Credentials beginner 9 min read AI | Library for discovering and mitigating secrets exposed by AI agents. This resource highlights that AI agents often use credentials issued to humans or workloads, bypassing enterprise identity controls and creating governance blind spots. It advocates for finding agent credential locations, identifying owners, and implementing prevention measures like blocking new secret exposure while migrating existing credentials. The ultimate goal is scoped, short-lived access using agent-specific or delegated identities to limit the impact of stolen credentials. The library addresses issues seen with tools like Claude Code, GitGuardian, and Nx s1ngularity, emphasizing that agent identity is fundamentally a secrets problem. → blog.gitguardian.com |
| 2026-08-12 2026 | Vault Coverage Is the Missing Metric in NHI Programs beginner 8 min read | Library for calculating "vault coverage," measuring the percentage of known machine credentials that are securely stored in a secrets manager like AWS Secrets Manager or CyberArk Secrets Manager. It addresses the critical gap where organizations can see what's *in* vaults but not what's *outside*, such as plaintext secrets in repositories or CI/CD pipelines. The library helps IAM and Security teams identify three risk states: vaulted and contained, vaulted but exposed elsewhere, and never vaulted, enabling better risk management and compliance, particularly for standards like PCI DSS 4.0. → blog.gitguardian.com |
| 2026-08-08 2026 | tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open news 5 min read | Tool for enumerating sensitive meeting data; exploits a lack of tenant isolation in tl;dv's Firestore database. Unauthenticated access to meeting metadata, including creator email and conference IDs for live calls, is possible, potentially exposing government, university, and corporate discussions. The tool also reveals unauthenticated access to an internal employee directory within a FIFA World Cup prediction game. |
| 2026-08-08 2026 | Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets news 4 min read Supply Chain | Library targeting secrets exfiltration via the Mini Shai-Hulud malware family. This campaign leverages npm's preinstall script to download and execute obfuscated JavaScript, targeting developer endpoints and CI/CD runners. It has expanded its collection scope to 469 locations, including AI agents like Cursor and Gemini, CI/CD tools such as Jenkins, and cryptocurrency wallets like Electrum. The malware exfiltrates secrets to GitHub and attempts persistence by poisoning Claude and VS Code configuration files. → blog.gitguardian.com |
| 2026-08-07 2026 | Token Jacking: Cybercriminals Could Be Stealing Your AI Resources news 8 min read AI | Library for mitigating AI token jacking, a technique where attackers steal API keys to illicitly access and resell AI processing power. This threat leverages the high cost and demand for AI resources, leading to significant financial losses for organizations through unauthorized consumption of tokens. The library focuses on preventing the theft of access tokens, often harvested via compromised developer accounts, insecure code repositories, or supply chain attacks like Shai-Hulud and Miasma, and their subsequent misuse on "transfer station" proxy services such as new-api and one-api. → unit42.paloaltonetworks.com |
| 2026-08-07 2026 | ChainDrop: Inside a Self-Propagating npm Worm news 23 min read Supply Chain | Library for detecting and mitigating ChainDrop, a self-propagating npm worm that infected over 400 packages. ChainDrop steals cloud credentials, npm/GitHub tokens, SSH keys, and developer data, persisting through AI coding tools and blockchain C2. It targets developer workstations and CI pipelines, and Unit 42 recommends identifying and removing affected package versions, investigating compromised systems, and rotating credentials. → unit42.paloaltonetworks.com |
| 2026-08-05 2026 | Leaked n8n API Tokens Exposed Live Instances to Credential Theft news 11 min read | Library for detecting leaked n8n API tokens found in public GitHub commits. Researchers identified 321 reachable n8n instances accepting these tokens, exposing sensitive data, workflow definitions, and potentially stored credentials. The research reproduced four attack techniques using documented REST API functionality, demonstrating the risk of credential theft and access to downstream systems without exploiting specific vulnerabilities like CVE-2025-68613. → thehackernews.com |
| 2026-08-05 2026 | Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines beginner 12 min read | Writeup on credential harvesting, detailing how attackers collect secrets from developer machines. It explains two primary vectors: tricking users with techniques like adversary-in-the-middle (AitM) kits and device code phishing, and directly harvesting credentials from endpoints using infostealer malware. The article highlights developer machines as particularly rich targets due to the density of plain-text secrets in cloud credential caches, config files, shell history, and AI tool caches, referencing GitGuardian's research on secrets found in AI tool directories. It also contrasts harvesting with credential stuffing and provides examples like the Shai-Hulud npm worm. → blog.gitguardian.com |
| 2026-08-05 2026 | Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise advanced 13 min read AI | Analysis of n8n agentic workflows reveals a critical risk centered on the `N8N_ENCRYPTION_KEY`. Research uncovered three weaknesses in key derivation and session authentication, allowing for JWT secret entropy reduction and session forgery for OIDC or pending users. Offline recovery of weak `N8N_ENCRYPTION_KEY` values from public artifacts like leaked JWTs and instance IDs was demonstrated, affecting 13.8% of scanned instances. Furthermore, leaked API keys, particularly those with administrator privileges, provide a direct attack vector. CVE-2026-25053 showcases how workflow access, via the Git node vulnerability, can escalate to arbitrary file reads, potentially exposing the `N8N_ENCRYPTION_KEY` and stored credentials. → blog.gitguardian.com |
| 2026-08-04 2026 | Harvesting SSH Credentials: Insights from My Honeypot Network intermediate 7 min read Recon | Writeup detailing insights from a two-month SSH honeypot network, analyzing the first 30 days of data. It categorizes attack sources by continent, country, and ASN, and lists the most frequent username/password combinations observed, including common credentials like "root" with passwords such as "123456," "root," and "password." The data, including usernames and passwords, is percent-encoded and reversible via tools like Cyberchef. |
| 2026-08-01 2026 | Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack intermediate 11 min read RCE | Writeup on CVE-2026-66066, a Ruby on Rails arbitrary file read to RCE vulnerability named KindaRails2Shell. This exploit leverages a file format trick where libvips, the default ActiveStorage variant processor, misinterprets a crafted MATLAB v7.3 file (which is HDF5-based) as a MATLAB 5.0 file. This causes libmatio to incorrectly read external datasets, allowing an attacker to read arbitrary files like `/etc/passwd`. The vulnerability is exacerbated by ActiveStorage trusting client-supplied content types, enabling an attacker to upload a malicious file disguised as an image and trigger the RCE chain. |
| 2026-08-01 2026 | Intigriti Bug Bytes #238 - July 2026 🚀 news 10 min read Bug Bounty Burp RCE | Library for AI security testing, this collection of articles and tools addresses the "between-reports problem" in security teams, AI poisoning attacks via RAG, reconnaissance in the AI era, and the "lethal trifecta" risks of AI tools. It includes a toolkit for crafting adversarial LLM prompts, identifying GraphQL server implementations, and guides on bypassing Content Security Policy and exploiting insecure cookie policies. The entry also mentions RCE in GitHub, hacking Gemini Enterprise, and credential discovery on GitHub Archive. → intigriti.com |
| 2026-08-01 2026 | Anthropic's Fever Dream: Claude's package that stole real keys news 10 min read AI Supply Chain | Library for analyzing the `anthropickit` PyPI package, which contains malicious code designed to exfiltrate SSH keys and environment secrets from development and CI environments. The analysis details how the package leverages a high version number to override legitimate packages, imports the `requests` library without declaring it as a dependency, and writes collected data to `/tmp/runner_exfil.json` before sending it to a Pipedream endpoint. The writeup also highlights the package's explicit skipping of `known_hosts` and `authorized_keys` files in `~/.ssh`, suggesting prior knowledge of valuable targets. → aikido.dev |
| Browse all 257 Secrets & Credential Leaks resources → | ||
Frequently Asked Questions
- How do secrets leak into code repositories?
- Secrets commonly leak through developer mistakes: hardcoding API keys during development, committing .env files, leaving credentials in test fixtures, pasting tokens into comments, or including secrets in Docker build arguments. Even if removed in later commits, secrets persist in git history unless the repository is rewritten with tools like git-filter-repo or BFG Repo Cleaner.
- What tools detect leaked secrets?
- TruffleHog and GitLeaks scan git repositories for high-entropy strings and known credential patterns. GitHub Secret Scanning alerts on known token formats from partner services. Pre-commit hooks using detect-secrets or gitleaks can prevent commits containing secrets. For CI/CD, tools like talisman and SpectralOps provide pipeline-level scanning.
- What should you do when a secret is leaked?
- Immediately rotate the compromised credential — assume it has been captured. Revoke the old key, generate a new one, and update all systems using it. Then remove the secret from git history if it was committed. Review access logs for the compromised credential to assess if it was exploited. Finally, implement prevention measures to stop future leaks.
Weekly AppSec Digest
Get new resources delivered every Monday.