Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

It Just Got Easier To Consistently Deploy And Configure ggshield Across Your Whole Fleet With v1.53

ggshield v1.53.0 introduces ggshield machine setup, a consistent way to configure ggshield no matter how it was installed. Set up AI hooks for every detected AI coding assistant, install global git pre-commit/pre-push hooks, and deploy a honeytoken on the endpoint. You have full control, and we have options to customize which features you want to skip. This release also includes ggshield machine doctor, a read-only command that checks that the machine's ggshield protections are correctly set up, letting you know what steps to take if it encounters an issue.

An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker

OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.

Every laptop is a credential store: lessons from Vermeer

Your code repos aren't the only place secrets hide — your laptop is too. In this session, GitGuardian's Emanuelle Franquelin talks with CJ May, Cybersecurity Architect at Vermeer, about extending secrets detection beyond the codebase and onto developer endpoints. They dig into where credentials actually live on modern machines (think config files, shell history, and AI coding agents), why every workstation is fair game, and what to actually do once you find exposed secrets. Watch to see how one enterprise team is tackling credential sprawl to deploy AI safely.