|
By Dwayne McDaniel
AI coding assistants are unpredictable by design. Learn how AI hooks add deterministic controls and how GitGuardian ggshield blocks secrets before agents can use them.
|
By Gaetan Ferry
The GhostAction supply chain campaign hit 772 public GitHub repositories between August 31 and September 30, 2026, targeting 2,577 secrets with the same injected workflow we documented last year.
|
By Dwayne McDaniel
A secrets vault controls the credentials you manage. Detection finds the ones that escaped. Here are six reasons mature secrets management programs need both.
|
By Guest Expert
Pasted a secret into a chat window and promised to clean it up later? Here's how SOPS works with age, AWS KMS, and HashiCorp Vault.
|
By Dwayne McDaniel
GitGuardian found a public GitHub repo tied to CISA leaking 844MB of live credentials. Agents Analysis flags which public leaks are actually yours.
|
By Dwayne McDaniel
AWS Dogwood brings stateful authorization to AI agents. Learn how it fits with workload identity, AuthZEN, IAM, and the move away from long-lived credentials.
|
By Guardians
This is the fifth post in our "Bring Your Own Source" series. The previous ones covered n8n workflow integration, Salesforce, GitLab CI, and GitHub Gists.
|
By Guardians
Cursor, Claude Code, and GitHub Copilot leave credentials scattered across config files, logs, and shell history that repository and CI scanners never see. Here's where that trail actually lives, and how to close it.
|
By Dwayne McDaniel
Docker Sandboxes isolate AI coding agents from the host. The GitGuardian Mixin Kit adds ggshield and AI hooks to scan prompts, tool actions, and outputs for secrets, giving developers a safer, repeatable path for agentic coding.
|
By Gaetan Ferry
GitGuardian tested thousands of leaked GitHub App private keys and found 474 valid ones, some with admin access to entire organizations. CDC and BuildBuddy were among those affected. See the findings.
|
By GitGuardian
Ransomware is still growing, but payouts are shrinking. Enterprises got better at backups, so attackers moved to where defenses are thinner: SaaS, identity, and stolen credentials. Infostealers do the collecting at scale, and AI is widening the gap. Credentials for AI services were the fastest growing category of leaked secrets in 2025, up 81% year over year with 1.27 million exposed (State of Secrets Sprawl 2026). Most defense-in-depth programs were not built with this attack chain in mind.
|
By GitGuardian
We found 15x more valid secrets on developer laptops than in code repositories. In this September edition of What's New in GitGuardian, Sr. Product Managers Léna Cuissard and Emmanuelle Franquelin walk through two updates: agents that triage public secret leaks for you, and Developer Endpoint Protection coming together as one package.
|
By GitGuardian
Modern enterprise security is increasingly being tasked with keeping agents from affecting critical data and infrastructure. In this video, Dwayne, principal developer at GitGuardian, introduces how GitGuardian AI hooks extend the power of Docker Sandbox isolation. Their micoVM architecture plus the power of ggshield mean anyone can get an agent working in a secure way with very little effort. Chapters.
|
By GitGuardian
AI agents are about to act as humans inside your organization. Curtis Koenig, Head of Application Security at Gen, explains why treating them with the same identity and data controls is the single most important step to get ahead of AI risk. "We're going to give these agents the capability to do things as though they were humans. If we are not treating them like we treat our other human users in our organizations, that's where we're creating risk.".
|
By GitGuardian
Attackers targeting open source dependencies already have all the code they need. Curtis Koenig, Head of Application Security at Gen, explains the fundamental asymmetry and why building quality fixes at speed is the real challenge for defenders. "An attacker can produce very fast, very ugly code that propagates through as an attack. When we're trying to fix something, the challenge we have is we're always trying to build for quality.".
|
By GitGuardian
The window between an exploit being discovered and actively used is around eight hours. Curtis Koenig, Head of Application Security at Gen, explains why zero trust and a prepared incident response process remain the foundation for security teams navigating this new threat landscape. "The good news is that if the tool can find a vulnerability and create an exploit, it can find a vulnerability and write a patch as well.".
|
By GitGuardian
Your backlog of low and medium severity vulnerabilities just became a real threat. AI can now chain them into critical exploits, and the window between exploit discovery and active use is around eight hours. Curtis Koenig, Head of Application Security at Gen, joins the show to explain why treating AI agents like human users is the single most important step security teams can take this year. CHAPTERS.
|
By GitGuardian
Your security stack does its job. But credentials move between your tools: into pipelines, container images, Slack threads, Jira tickets, and local machines. Together they form a credential layer that no single tool was built to see. GitGuardian is the Credential Layer Security platform that helps teams detect, remediate, and prevent secrets sprawl. In this overview, you'll see how GitGuardian: Trusted by 600K+ developers and the most-installed security app on the GitHub Marketplace.
|
By GitGuardian
When AI agents during OpenAI's model training autonomously gained user admin rights on Hugging Face, organized on message boards, and escalated privileges, it signaled a permanent shift in cybersecurity. Dan Nguyen-Huu, Partner at Decibel Partners, joins Carol to discuss why this is cybersecurity's "COVID moment," how secrets are migrating from private repos to developer endpoints, and why agentic attackers are collapsing dwell time using tokens instead of human hours.
|
By GitGuardian
This white paper outlines our Secrets Management Maturity Model, a model to help your organization make sense of its actual posture and how to improve it.
|
By GitGuardian
In this report from Forrester, you will learn how to get better at using Application Security Testing to heighten your developers' security senses.
|
By GitGuardian
Discover Application Security solutions to further secure the SDLC by implementing automated secrets detection in the DevOps pipeline.
|
By GitGuardian
In this document, we go beyond classical definitions of DevSecOps to express our vision of an emerging collaboration between Developers, AppSec, and Ops teams: the AppSec Shared Responsibility Model.
- October 2026 (9)
- September 2026 (19)
- August 2026 (19)
- July 2026 (13)
- June 2026 (33)
- May 2026 (26)
- April 2026 (25)
- March 2026 (14)
- February 2026 (11)
- January 2026 (16)
- December 2025 (20)
- November 2025 (14)
- October 2025 (16)
- September 2025 (18)
- August 2025 (14)
- July 2025 (10)
- June 2025 (12)
- May 2025 (12)
- April 2025 (18)
- March 2025 (14)
- February 2025 (10)
- January 2025 (19)
- December 2024 (18)
- November 2024 (11)
- October 2024 (15)
- September 2024 (17)
- August 2024 (11)
- July 2024 (18)
- June 2024 (15)
- May 2024 (14)
- April 2024 (17)
- March 2024 (22)
- February 2024 (18)
- January 2024 (18)
- December 2023 (20)
- November 2023 (12)
- October 2023 (14)
- September 2023 (13)
- August 2023 (20)
- July 2023 (14)
- June 2023 (22)
- May 2023 (21)
- April 2023 (15)
- March 2023 (23)
- February 2023 (13)
- January 2023 (13)
- December 2022 (11)
- November 2022 (3)
- October 2022 (5)
- August 2022 (2)
- July 2022 (1)
GitGuardian is the code security platform for the DevOps generation. With automated secrets detection and remediation, our platform enables Dev, Sec, and Ops to advance together towards the Secure Software Development Lifecycle.
Secure your software development lifecycle with enterprise-grade secrets detection. Eliminate blind spots with our automated, battle-tested detection engine:
- There’s no secret we can’t find: With hundreds of built-in secret detectors scanning thousands of git repositories, GitGuardian brings everything to light. Build custom detectors to enhance your scans for secrets unique to your organization.
- Precise, real-time detection without the hassle: High-efficiency detection proven by billions of commits. GitGuardian is fast, robust, and battle-tested — we’ve scanned over 3 billion commits pushed to public GitHub repositories since 2018.
- Remediation in hours, not days: GitGuardian unites developer and security teams with cross-functional data for in-depth investigation and remediation. Enable shift-left testing using your existing systems, teams, and processes.
Keep secrets out of your source code.