A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.
Credential harvesting is how attackers collect valid secrets at scale. See how it works, why developer machines are a prime target, and how to find them first.
Your.env file has your database password, your AWS keys, and your Stripe secret, all in plaintext, sitting on your laptop. 1Password Developer Watchtower finds it, 1Password Environments secures it, and you keep shipping. See how 1Password discovers plaintext developer credentials, imports them into an encrypted environment, and mounts a virtual protected.env, with no workflow disruption for developers and full fleet visibility for security teams.
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
Developers, how are you managing your secrets? Keeper Security’s Universal Secrets Sync automatically distributes credentials and secrets stored in Keeper to external secrets managers and cloud platforms, including AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager.
This article was co-written by Zach Rice and Joe Leon, both at Aikido Security. tl;dr Some credentials are meant to be public, but secret scanners still flag them as generic secrets. We wrote suppression rules for the most common ones and reduced false positives by ~2%. These rules now ship by default in Betterleaks. Secrets scanners are built on regular expressions. Each pattern targets a specific credential type, like an AWS secret access key, a GitHub PAT, or a Stripe token.
Learn how to measure time to revoke for exposed credentials using validation and invalidation timestamps, remediation SLAs, and CISO reporting metrics.
Learn why modern identity infrastructure security depends on credential exposure detection, not just directory management, and how to close the gaps that lead to breaches.
After the CISA GitHub leak, the agency published a candid incident postmortem. Here are six lessons security teams should copy, from secrets scanning to key rotation.
GitGuardian is now live on the Kiro Powers marketplace. Install the Power once, and Kiro's agent scans for exposed secrets automatically every time it writes or modifies code that handles credentials.