Secrets & Credential Leaks
Secrets management and credential leak prevention address one of the most common and impactful security failures in modern software development. Hardcoded API keys, database passwords, cloud credentials, and private keys regularly appear in source code repositories, CI/CD configurations, container images, client-side JavaScript, and log files. Tools like TruffleHog, GitLeaks, and GitHub Secret Scanning detect exposed credentials in repositories, while vault solutions like HashiCorp Vault, AWS Secrets Manager, and cloud KMS services provide secure runtime secret injection. The impact of leaked credentials can be devastating — exposed AWS keys can lead to full cloud account compromise within minutes, and leaked database credentials can result in complete data breaches. Prevention requires secrets scanning in CI/CD pipelines, pre-commit hooks, environment-based secret injection, and credential rotation policies.
| Date Added | Link | Excerpt |
|---|---|---|
| 2026-04-22 NEW 2026 | UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours | UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours |
| 2026-04-22 NEW 2026 | The State of Non-Human Identity Security (CSA Survey Report) | The State of Non-Human Identity Security (CSA Survey Report) |
| 2026-04-22 NEW 2026 | Secrets Management in 2026: Vault, AWS Secrets Manager, and Beyond | Secrets Management in 2026: Vault, AWS Secrets Manager, and Beyond |
| 2026-04-22 NEW 2026 | GitHub Secret Scanning 2026: New Patterns, Push Protection | GitHub Secret Scanning 2026: New Patterns, Push Protection |
| 2026-04-22 NEW 2026 | Top 10 Non-Human Identity Security Tools and Platforms for 2026 | Top 10 Non-Human Identity Security Tools and Platforms for 2026 |
| 2026-04-22 NEW 2026 | CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token Generation | CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token Generation |
| 2026-04-22 NEW 2026 | CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS) | CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS) |
| 2026-04-22 NEW 2026 | AI Is Fueling Secrets Sprawl: GitGuardian Reports 81% Surge of AI-Service Leaks | AI Is Fueling Secrets Sprawl: GitGuardian Reports 81% Surge of AI-Service Leaks |
| 2026-04-22 NEW 2026 | HCSEC-2026-08: Vault DoS via Unauthenticated Root Token Generation | HCSEC-2026-08: Vault DoS via Unauthenticated Root Token Generation |
| 2026-04-22 NEW 2026 | HCSEC-2026-05: Vault KVv2 Metadata Policy Bypass DoS | HCSEC-2026-05: Vault KVv2 Metadata Policy Bypass DoS |
| 2026-04-19 NEW 2026 | Compromised IAM Credentials Power Large AWS Crypto Mining Campaign | Compromised IAM Credentials Power Large AWS Crypto Mining Campaign |
| 2026-04-19 NEW 2026 | Pre-Commit Hooks for Secret Detection: Setup in 10 Minutes | Pre-Commit Hooks for Secret Detection: Setup in 10 Minutes |
| 2026-04-19 NEW 2026 | Understanding Your Organization's Exposure to Secret Leaks — GitHub | Understanding Your Organization's Exposure to Secret Leaks — GitHub |
| 2026-04-19 NEW 2026 | Exposed Developer Secrets Surge: AI Drives 34% Increase in 2025 | Exposed Developer Secrets Surge: AI Drives 34% Increase in 2025 |
| 2026-04-19 NEW 2026 | GitHub Found 39M Secret Leaks in 2024 — The GitHub Blog | GitHub Found 39M Secret Leaks in 2024 — The GitHub Blog |
| 2026-04-17 NEW 2026 | Non-human identities: What they are and how to secure them (Netwrix) | Non-human identities: What they are and how to secure them (Netwrix) |
| 2026-04-17 NEW 2026 | Top non-human identity (NHI) platforms of 2025 (Doppler) | Top non-human identity (NHI) platforms of 2025 (Doppler) |
| 2026-04-17 NEW 2026 | What Are Non-Human Identities? Complete NHI Security Guide 2025 | What Are Non-Human Identities? Complete NHI Security Guide 2025 |
| 2026-04-17 NEW 2026 | TruffleHog: Deep Dive on Secret Management (Jit) | TruffleHog: Deep Dive on Secret Management (Jit) |
| 2026-04-17 NEW 2026 | TruffleHog Open Source v3 vs GitGuardian | TruffleHog Open Source v3 vs GitGuardian |
| 2026-04-17 NEW 2026 | git-secret-scanner: Find secrets with TruffleHog & Gitleaks | git-secret-scanner: Find secrets with TruffleHog & Gitleaks |
| 2026-04-17 NEW 2026 | Gitleaks vs TruffleHog 2026 Benchmarks (AppSec Santa) | Gitleaks vs TruffleHog 2026 Benchmarks (AppSec Santa) |
| 2026-04-17 NEW 2026 | Rafter: detect-secrets vs gitleaks vs TruffleHog | Rafter: detect-secrets vs gitleaks vs TruffleHog |
| 2026-04-17 NEW 2026 | SEC02-BP03 Store and use secrets securely (AWS Well-Architected) | SEC02-BP03 Store and use secrets securely (AWS Well-Architected) |
| 2026-04-17 NEW 2026 | AWS Secrets Manager: Secure Credential Storage & Best Practices | AWS Secrets Manager: Secure Credential Storage & Best Practices |
| 2026-04-17 NEW 2026 | Practical steps to minimize key exposure using AWS Security (AWS) | Practical steps to minimize key exposure using AWS Security (AWS) |
| 2026-04-17 NEW 2026 | AWS API Keys / Secrets / Tokens Exposure Remediation | AWS API Keys / Secrets / Tokens Exposure Remediation |
| 2026-04-17 NEW 2026 | Integrating HashiCorp Vault with Kubernetes for Secrets Mgmt | Integrating HashiCorp Vault with Kubernetes for Secrets Mgmt |
| 2026-04-17 NEW 2026 | HashiCorp Vault Kubernetes: The Definitive Guide (Plural) | HashiCorp Vault Kubernetes: The Definitive Guide (Plural) |
| 2026-04-17 NEW 2026 | A Hands-On Guide to Vault in Kubernetes | A Hands-On Guide to Vault in Kubernetes |
| 2026-04-17 NEW 2026 | Securing Kubernetes Secrets with HashiCorp Vault (InfraCloud) | Securing Kubernetes Secrets with HashiCorp Vault (InfraCloud) |
| 2026-04-17 NEW 2026 | Manage Kubernetes native secrets with Vault Secrets Operator | Manage Kubernetes native secrets with Vault Secrets Operator |
| 2026-04-17 NEW 2026 | Secret detection (GitLab Docs) | Secret detection (GitLab Docs) |
| 2026-04-17 NEW 2026 | Find secrets with GitHub secret risk assessment | Find secrets with GitHub secret risk assessment |
| 2026-04-17 NEW 2026 | About secret scanning (GitHub Docs) | About secret scanning (GitHub Docs) |
| 2026-04-16 NEW 2026 | Do Not Use Secrets in Environment Variables | Do Not Use Secrets in Environment Variables |
| 2026-04-16 NEW 2026 | Environment Variables Don't Keep Secrets | Environment Variables Don't Keep Secrets |
| 2026-04-16 NEW 2026 | From .env to Leakage: Mishandling of Secrets by Coding Agents | From .env to Leakage: Mishandling of Secrets by Coding Agents |
| 2026-04-16 NEW 2026 | Secret Detection in Application Security | Secret Detection in Application Security |
| 2026-04-16 NEW 2026 | 29 Million Leaked Secrets: How AI Coding Tools Are Making It Worse | 29 Million Leaked Secrets: How AI Coding Tools Are Making It Worse |
| 2026-04-16 NEW 2026 | The State of Secrets Sprawl 2026 - GitGuardian Annual Report | The State of Secrets Sprawl 2026 - GitGuardian Annual Report |
| 2026-04-11 2026 | Terraform Secrets Management Best Practices | Terraform Secrets Management Best Practices |
| 2026-04-11 2026 | AWS IAM Roles Anywhere Workload Identities | AWS IAM Roles Anywhere Workload Identities |
| 2026-04-11 2026 | External Secrets Operator: Introduction | External Secrets Operator: Introduction |
| 2026-04-11 2026 | Google Cloud SIEM Service Account Token Leak | Google Cloud SIEM Service Account Token Leak |
| 2026-04-11 2026 | Secret Rotation: How It Works | Secret Rotation: How It Works |
| 2026-04-11 2026 | Secret Auto Rotation with Secrets Store CSI Driver | Secret Auto Rotation with Secrets Store CSI Driver |
| 2026-04-11 2026 | Secretless GitHub Actions to AWS via OIDC | Secretless GitHub Actions to AWS via OIDC |
| 2026-04-11 2026 | OIDC Security Hardening for GitHub Actions | OIDC Security Hardening for GitHub Actions |
| 2026-04-11 2026 | Hardening HashiCorp Vault Best Practices | Hardening HashiCorp Vault Best Practices |
| 2026-04-11 2026 | HashiCorp Vault Production Hardening Guide | HashiCorp Vault Production Hardening Guide |
| 2026-04-11 2026 | Leaked Env Variables Allow Large-Scale Cloud Extortion | Leaked Env Variables Allow Large-Scale Cloud Extortion |
| 2026-04-11 2026 | CVE-2025-68429: Storybook .env Secrets Exposure | CVE-2025-68429: Storybook .env Secrets Exposure |
| 2026-04-11 2026 | 10K Docker Images Spray Live Cloud Creds | 10K Docker Images Spray Live Cloud Creds |
| 2026-04-11 2026 | 10,000+ Docker Hub Images Leaking Credentials | 10,000+ Docker Hub Images Leaking Credentials |
| 2026-04-11 2026 | Thousands of Secrets Exposed on Docker Hub | Thousands of Secrets Exposed on Docker Hub |
| 2026-04-11 2026 | What Happens When You Leak AWS API Keys? | What Happens When You Leak AWS API Keys? |
| 2026-04-11 2026 | CloudKeys in the Air: Exposed IAM Keys Cryptojacking | CloudKeys in the Air: Exposed IAM Keys Cryptojacking |
| 2026-04-11 2026 | AWS Customer Security Incidents Repository | AWS Customer Security Incidents Repository |
| 2026-04-11 2026 | 2,622 Valid Certificates Exposed: Google-GitGuardian Study | 2,622 Valid Certificates Exposed: Google-GitGuardian Study |
| 2026-04-11 2026 | 8000+ ChatGPT API Keys Exposed on GitHub | 8000+ ChatGPT API Keys Exposed on GitHub |
| 2026-04-11 2026 | Secret Scanning in CI Pipelines using Gitleaks | Secret Scanning in CI Pipelines using Gitleaks |
| 2026-04-11 2026 | Add a Local Gitleaks Pre-Commit Hook | Add a Local Gitleaks Pre-Commit Hook |
| 2026-04-11 2026 | GitHub Comments Leak Live API Keys | GitHub Comments Leak Live API Keys |
| 2026-04-11 2026 | Secret Scanning Encoded and Archived Data | Secret Scanning Encoded and Archived Data |
| 2026-04-11 2026 | How TruffleHog Verifies Secrets | How TruffleHog Verifies Secrets |
| 2026-04-10 2026 | Secret Scanner Comparison: Finding Your Best Tool | Secret Scanner Comparison: Finding Your Best Tool |
| 2026-04-10 2026 | 6 Effective Secret Scanning Tools | 6 Effective Secret Scanning Tools |
| 2026-04-10 2026 | Top 8 Git Secrets Scanners in 2026 | Top 8 Git Secrets Scanners in 2026 |
| 2026-04-10 2026 | 8 Best Secret Scanning Tools (2026) | 8 Best Secret Scanning Tools (2026) |
| 2026-04-10 2026 | Best Secret Scanning Tools in 2025 | Best Secret Scanning Tools in 2025 |
| 2026-04-10 2026 | GitHub Leaked API Keys and Secrets Reference | GitHub Leaked API Keys and Secrets Reference |
| 2026-04-10 2026 | 23.8 Million Secrets Leaked on GitHub: The Case for Expiring Credentials | 23.8 Million Secrets Leaked on GitHub: The Case for Expiring Credentials |
| 2026-04-10 2026 | 29 Million Secrets Leaked on GitHub: AI Coding Tools Made It Worse | 29 Million Secrets Leaked on GitHub: AI Coding Tools Made It Worse |
| 2026-04-10 2026 | GitHub is Awash with Leaked AI Company Secrets | GitHub is Awash with Leaked AI Company Secrets |
| 2026-04-10 2026 | The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% | The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% |
| 2026-04-10 2026 | State of Secrets Sprawl Report 2025 | State of Secrets Sprawl Report 2025 |
| 2026-04-10 2026 | AI Frenzy Feeds Credential Chaos | AI Frenzy Feeds Credential Chaos |
| 2026-04-10 2026 | GitHub Secret Leaks: 13 Million API Credentials in Public Repos | GitHub Secret Leaks: 13 Million API Credentials in Public Repos |
| 2026-04-10 2026 | Best Secret Scanning Tools For 2026 | Best Secret Scanning Tools For 2026 |
| 2026-04-10 2026 | 29 Million Secrets Leaked: AI Coding Tools Making It Worse | 29 Million Secrets Leaked: AI Coding Tools Making It Worse |
| 2026-04-10 2026 | The State of Secrets Sprawl 2026: 9 Takeaways for CISOs | The State of Secrets Sprawl 2026: 9 Takeaways for CISOs |
| 2026-04-10 2026 | The State of Secrets Sprawl 2025 | The State of Secrets Sprawl 2025 |
| 2026-04-10 2026 | The Complete 2026 Secrets Management Guide | The Complete 2026 Secrets Management Guide |
| 2026-04-06 2026 | Zen AI Pentest GitHub Action | Zen AI Pentest GitHub Action |
| 2026-04-06 2026 | Shift Left Security That Developers Actually Keep Enabled | Shift Left Security That Developers Actually Keep Enabled |
| 2026-04-06 2026 | CERT-EU Confirms Trivy Supply Chain Attack Led to Credential Exposure | CERT-EU Confirms Trivy Supply Chain Attack Led to Credential Exposure |
| 2026-04-06 2026 | The Claude Code Security Checklist: What the Source Code Reveals | The Claude Code Security Checklist: What the Source Code Reveals |
| 2026-04-06 2026 | Hardcoded Secrets in AI-Generated Code: Catch Them Before They Ship | Hardcoded Secrets in AI-Generated Code: Catch Them Before They Ship |
| 2026-04-03 2026 | AWS Secrets Manager vs HashiCorp Vault [2026] | AWS Secrets Manager vs HashiCorp Vault [2026] |
| 2026-04-03 2026 | AWS Secrets Engine | HashiCorp Vault | AWS Secrets Engine | HashiCorp Vault |
| 2026-04-03 2026 | Researcher Unearths Thousands of Leaked Secrets in GitHub's "Oops Commits" | Researcher Unearths Thousands of Leaked Secrets in GitHub's "Oops Commits" |
| 2026-04-03 2026 | How to Detect and Clean Up Leaked Secrets in Your Git Repositories | How to Detect and Clean Up Leaked Secrets in Your Git Repositories |
| 2026-04-03 2026 | Secret Scanning Tools 2026: Protect Code and Prevent Credential Leaks | Secret Scanning Tools 2026: Protect Code and Prevent Credential Leaks |
| 2026-04-03 2026 | TruffleHog vs. Gitleaks: A Detailed Comparison | TruffleHog vs. Gitleaks: A Detailed Comparison |
| 2026-04-03 2026 | Why 28 Million Credentials Leaked on GitHub in 2025 | Snyk | Why 28 Million Credentials Leaked on GitHub in 2025 | Snyk |
| 2026-04-03 2026 | Gitleaks - Find Secrets with Gitleaks | Gitleaks - Find Secrets with Gitleaks |
| 2026-04-03 2026 | TruffleHog - Find, Verify, and Analyze Leaked Credentials | TruffleHog - Find, Verify, and Analyze Leaked Credentials |
| 2026-04-03 2026 | Secrets Management - OWASP Cheat Sheet Series | Website with the collection of all the cheat sheets of the project. |
Frequently Asked Questions
- How do secrets leak into code repositories?
- Secrets commonly leak through developer mistakes: hardcoding API keys during development, committing .env files, leaving credentials in test fixtures, pasting tokens into comments, or including secrets in Docker build arguments. Even if removed in later commits, secrets persist in git history unless the repository is rewritten with tools like git-filter-repo or BFG Repo Cleaner.
- What tools detect leaked secrets?
- TruffleHog and GitLeaks scan git repositories for high-entropy strings and known credential patterns. GitHub Secret Scanning alerts on known token formats from partner services. Pre-commit hooks using detect-secrets or gitleaks can prevent commits containing secrets. For CI/CD, tools like talisman and SpectralOps provide pipeline-level scanning.
- What should you do when a secret is leaked?
- Immediately rotate the compromised credential — assume it has been captured. Revoke the old key, generate a new one, and update all systems using it. Then remove the secret from git history if it was committed. Review access logs for the compromised credential to assess if it was exploited. Finally, implement prevention measures to stop future leaks.
Weekly AppSec Digest
Get new resources delivered every Monday.