Sign in

GitGuardian

@gitguardian.com
207 followers 124 following 91 posts

GitGuardian: The Credential Layer Security Platform, helping enterprises close credential-based breach paths. Website: gitguardian.com Blog: blog.gitguardian.com Free GH audit: s.gitguardian.com/free-audit

PostsRepliesMedia
Reposted by GitGuardian
Cyber Insurance News @cyberinsurancenews.bsky.social · 16/06/2026
Developer Laptops Are Now Credential Stores – Underwriters Should Treat Them That Way GitGuardian moved on that shift today, launching Developer Endpoint Protection. Read all about it - cyberinsurancenews.org/cyber-insura... #cyberinsurance #cybersecurity @gitguardian.com
cyberinsurancenews.org
Developer Laptops Are Now Credential Stores - Underwriters Should Treat Them That Way
Estimated reading time: 7 minutes For a decade, the secret-sprawl problem lived in source code. The supply-chain campaigns of the past year moved it onto
001
GitGuardian @gitguardian.com · 12/06/2026
A historical scan can surface hundreds or thousands of incidents at once. GitGuardian's incident table is built to answer what to work on first: verified validity, automated severity scoring across 24 rule sets, and saved filtered views. youtu.be/Fhj83rW1lOQ
youtu.be
Prioritizing Your GitGuardian Incidents
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 10/06/2026
ggshield can plant honey tokens directly from your terminal. Decoy AWS keys that look real, grant no access, and alert you the moment someone tries to use them. Trip wires for your codebase. youtu.be/UsLGa44CugM
youtu.be
Honeytokens with ggshield: plant tripwires that alert on secret use
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 09/06/2026
GitGuardian now scans Gerrit. Full historical scan on connect, real-time scanning on every new commit and comment. Findings land in the same dashboard as your GitHub, GitLab, and Bitbucket incidents. youtu.be/q1XzY6HvxAI
youtu.be
Secrets Are Hiding in Your Gerrit Code Reviews — Here's How to Find Them
YouTube video by GitGuardian
011
GitGuardian @gitguardian.com · 08/06/2026
AI coding assistants read files, run commands, and call tools. ggshield AI hooks scan at each of those points and block secrets before they reach prompts, logs, or generated code. One install command. Works with Cursor, Claude Code, and Copilot. youtu.be/he0Ynu32puQ
youtu.be
Stop Cursor, Claude Code & GitHub Copilot From Leaking Secrets With ggshield AI Hooks
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 05/06/2026
GitGuardian's updated search bar lets you triage incidents by pasting a secret value, typing an author email, a file path, or plain language like "open critical unassigned cloud incidents." Available now on every plan. youtu.be/LSrBUCvJaLM
youtu.be
GitGuardian’s Smarter Search Bar Makes Incident Triage Faster
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 04/06/2026
When a breach happens, you need to account for every secret: which were in CI, which were on developer laptops, which processes had access. That inventory is what you show your board. youtube.com/shorts/EOrZm...
youtube.com
You need to put secret analysis into your forensic investigation and your remediation process
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 03/06/2026
When an LLM hits a security constraint, GitGuardian research shows it often goes around it, silently, and hardcodes the secret. The developer didn't make that call. The model did. youtube.com/shorts/999wS...
youtube.com
LLMs go around that security constraint and hardcode secrets
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 02/06/2026
GitGuardian's VS Code extension now shows all secret findings in a sidebar panel — across every file, before you commit. Works in Cursor and Windsurf too. Catch it on save, not in CI. youtu.be/d18uYyOhez8
youtu.be
GitGuardian's VS Code Extension Just Made It Even Easier To Fight Secrets Sprawl
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 01/06/2026
One stolen PAT in February. Trivy poisoned March 19. Eight days later: Aqua, Checkmarx, LiteLLM, and Telnyx all compromised because they automatically consumed the update. This is what supply chain cascade looks like. youtube.com/shorts/qa-47...
youtube.com
From Trivy to Telnex...A malware in the supply chain timeline
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 29/05/2026
ggshield 1.51: AI hooks now cover Codex alongside #Claude, #ChatGPT, and #Cursor. #MCP server discovery extended to plugin-installed servers. Plus oob (out-of-band) auth, better SLSA provenance, and improved API status. youtu.be/RCIeYF3nkn0
youtu.be
New in ggshield 1.51: Codex Hooks, MCP Discovery, and SLSA Provenance
YouTube video by GitGuardian
030
GitGuardian @gitguardian.com · 28/05/2026
Claude Code co-authored commits leak secrets at 2.4× the human baseline. Larger commits, more lines, more exposure surface. AI speeds up development — and quietly expands the attack surface. youtube.com/shorts/9jEDl...
youtube.com
Claude Code Co-authored Commits Leak Secrets At 2× The Baseline
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 27/05/2026
Claude Code co-authored commits leak secrets at 2.4× the human baseline. Larger commits, more lines, more exposure surface. AI speeds up development — and quietly expands the attack surface. youtube.com/shorts/9jEDl...
youtube.com
Claude Code Co-authored Commits Leak Secrets At 2× The Baseline
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 21/05/2026
A CISA contractor pushed AWS GovCloud admin keys to a public GitHub repo in November. It sat there for 6 months, after GitGuardian sent 7–10 alerts. No response. Guillaume Valadon walks us through how we escalated this disclosure: youtu.be/mWIgasN3K7Q
youtu.be
An inside look at finding Leaked CISA AWS GovCloud Admin Keys on Github
YouTube video by GitGuardian
010
GitGuardian @gitguardian.com · 20/05/2026
Exploiting a vulnerability targets production. Malware targets the developer. That's not a subtle difference: it's where the credentials live: youtube.com/shorts/2-9e4...
youtube.com
Malware is created by criminals
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 18/05/2026
75,000 open incidents is normal for GitGuardian customers. A "generic IAM copy" enriched to "Microsoft credential, publicly leaked" = risk score 100. That's ML-powered triage in practice: youtu.be/iyKHvK3g9g8
youtu.be
Stop Drowning in Security Alerts — ML-Powered Incident Scoring Finds What Actually Matters
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 15/05/2026
After a developer machine compromise: what secrets were exposed, where, and what needs rotation now? GitGuardian Developer Endpoint Protection scans your fleet via MDM and answers all three: youtu.be/IDzSiJQCZZA
youtu.be
What Secrets Are on Your Developer Laptops? GitGuardian Developer Endpoint Protection Can Tell You
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 14/05/2026
Every time a developer pushes a secret to public GitHub, GitGuardian emails them directly. That's the Good Samaritan program. Millions of alerts sent per year: youtube.com/shorts/dUzjI...
youtube.com
GitGuardian's Good Samaritan Program Alerts Millions Of Devs Per Year About Leaked Secrets
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 13/05/2026
Gerrit is one of the most widely deployed code review platforms in enterprise environments, yet a blind spot for secrets detection. GitGuardian now scans it, historically and in real time: youtu.be/q1XzY6HvxAI
youtu.be
Secrets Are Hiding in Your Gerrit Code Reviews — Here's How to Find Them
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 12/05/2026
.env files are plain text secrets on a machine that's a supply chain target. ggshield 1.50 moves API tokens to your OS credential store by default and extends AI hooks to the MCP layer. Full breakdown: youtu.be/4c983T8hAyc
youtu.be
Why Storing Secrets in .env Files Is a Supply Chain Risk — And How ggshield 1.50 Fixes It
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 11/05/2026
Cmd+K from anywhere in GitGuardian and jump to incidents, settings, integrations, or docs without leaving your workspace. Context-aware, role-scoped. Small thing, saves real time mid-incident: youtu.be/Jx-RpuMX7ak
youtu.be
Cmd+K for Security: Navigate GitGuardian at the Speed of Thought
YouTube video by GitGuardian
000
GitGuardian @gitguardian.com · 08/05/2026
Ask GitGuardian "what are my top 10 public incidents right now?" and it answers. Natural language triage against all your incidents, in-app. Same 23 tools as the MCP server. Full demo: youtu.be/AqVPvAjkGR0
youtu.be
Meet GitGuardian's AI Assistant: Natural Language Queries Across All Your Incidents
YouTube video by GitGuardian
100
Reposted by GitGuardian
TruStory FM @trustory.fm · 04/03/2026
New Episode • Built Fast, Broken Faster: MCP & AI App Security—with GitGuardian’s Gaetan Ferry trustory.fm/cybersentries/built-fas…
001
GitGuardian @gitguardian.com · 17/02/2026
90B events/day and we’re still manually doing L1 triage? That’s not resilience, that’s ✨tradition✨. #ChiBrrCon 2026 takeaway: automate the repetitive, keep humans for judgment, and build real inventories. #AppSec #AI blog.gitguardian.com/chibrrcon-20...
blog.gitguardian.com
AI Is Making Security More Agile: Highlights from ChiBrrCon 2026
ChiBrrCon 2026 tackled AI, resilience, and operational agility in enterprise security. Learn what top speakers shared on SOC modernization and architectural risk.
000
Reposted by GitGuardian
Help Net Security @helpnetsecurity.com · 28/01/2026
Why prevention-first secrets security will define enterprise scale: Learnings from a leading telecom 📖 Read more: www.helpnetsecurity.com/2026/01/28/g... #cybersecurity #cybersecuritynews #telecommunications #remediation @gitguardian.com
helpnetsecurity.com
Why prevention-first secrets security will define enterprise scale: Learnings from a leading telecom - Help Net Security
GitGuardian enables prevention-first security by stopping secrets before Git commits, reducing leaks and helping teams scale safer.
011
Reposted by GitGuardian
InfoSecSherpa 🏔️ Lake Ontario 🚣‍♀️ @infosecsherpa.bsky.social · 28/01/2026
Cheat Sheet Alert! "How To Use ggshield To Avoid Hardcoded Secrets" by Dwayne McDaniel from @gitguardian.com December 10, 2025. GitGuardian's ggshield can help you quickly find any secrets in your repos, local files, archives, and commits. cybersec.gitguardian.com/s/how-to-use...
GitGuardian Security Your Secrets with ggshield
054
GitGuardian @gitguardian.com · 30/01/2026
🤖 Agents don’t log in. They act. At #NHIcon 2026 the message was clear: human-centric IAM breaks in the age of agentic AI. Static roles + long-lived creds = 🚨 risk amplification. Time for identity at the speed of autonomy. 🔐 blog.gitguardian.com/nhicon-2026
blog.gitguardian.com
Agentic AI and Non‑Human Identities Demand a Paradigm Shift In Security: Lessons from NHIcon 2026
In the race to innovate, software has repeatedly reinvented how we define identity, trust, and access. In the 1990's, the web made every server a perimeter. In the 2010's, the cloud made every identit...
020
GitGuardian @gitguardian.com · 22/01/2026
Secrets sprawl ≠ developer mistakes. It’s unmanaged machine access at scale. Boards care about downtime, cost, and resilience, and NHIs sit right in the middle. Here’s how to connect the dots 👇 blog.gitguardian.com/boards-focus...
blog.gitguardian.com
Boards Focus On Risk, Resilience, and Operational Realities: Where NHI Governance Fits In
Learn how GitGuardian helps boards and CISOs align on cyber risk, operational resilience, and the rising impact of unmanaged workload identities at scale.
000
GitGuardian @gitguardian.com · 12/01/2026
AI agents aren’t your coworkers. They’re over-permissioned bots with access to prod. Stop pretending they’re cute. Start treating them like risks. 🛑 NHI governance now! blog.gitguardian.com/what-ai-agen...
blog.gitguardian.com
What AI Agents Can Teach Us About NHI Governance
Agentic AI is a stress test for non-human identity governance. Discover how and why identity, trust, and access control must evolve to keep automation safe.
000
GitGuardian @gitguardian.com · 07/01/2026
AI agents are already causing incidents, and identity controls aren’t ready. Jan 27: Join GitGuardian at #NHIcon2026. Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social Free registration here: aembit.io/nhicon?aff=G...
aembit.io
NHIcon 2026 by Aembit | Jan. 27
Agentic software is moving fast. NHIcon 2026 is one-day virtual experience for platform and security pros tackling AI and non-human identity challenges.
000
Reposted by GitGuardian
OWASP London Chapter @owasplondon.bsky.social · 07/01/2026
The next OWASP London Chapter in-person Meetup will take place on January 21st, 2026, kindly sponsored by @nuaware_tech with raffle prizes kindly sponsored by @GitGuardian and @Docker Register to attend this event here: 👇
meetup.com
OWASP London Chapter Meetup [IN-PERSON], Wed, Jan 21, 2026, 6:00 PM | Meetup
**This event is kindly sponsored by Nuaware.** **Raffle prizes are kindly sponsored by GitGuardian and Docker.** **There is limited seating available for in-person attende
012
GitGuardian @gitguardian.com · 19/12/2025
Andy Rea built a demo showing how to wire up multiple AI agents using Google's Agent Development Kit (ADK) and the #A2A protocol, with GitGuardian scanning content for secrets. blog.gitguardian.com/building-a-m... The complete code is available at: github.com/reaandrew/a2...
110
GitGuardian @gitguardian.com · 17/12/2025
🚀 The future of secure non‑human identity is here! AWS IAM Outbound Identity Federation eliminates long‑term creds in favor of short‑lived tokens. GitGuardian can help you track the migration in real time. blog.gitguardian.com/aws-iam-outb... #DevSecOps #AppSec
blog.gitguardian.com
Getting To AWS IAM Outbound Identity Federation With GitGuardian
Secure all your non-human identities across providers and without secrets. Explore how AWS and GitGuardian can help organizations migrate to short-lived tokens.
000
GitGuardian @gitguardian.com · 05/12/2025
Secrets leaked? Don’t panic—push to vault! 🧯 GitGuardian's Push-to-Vault turns “uh-oh” into “handled” by sending secrets straight into your existing Secret Manager. No more tab juggling. blog.gitguardian.com/push-to-vault/
blog.gitguardian.com
From Detection to Defense: How Push-to-Vault Supercharges Secrets Management for DevSecOps
Secrets don’t belong in plaintext. GitGuardian's Push-to-Vault automates vaulting exposed secrets, helping security teams scale governance and reduce incident fatigue.
000
GitGuardian @gitguardian.com · 03/12/2025
🔄 Feature flags, legacy systems, and N+1 queries walk into a dev conf... /dev/mtl 2025 reminds us: it’s not about speed, it’s about smart feedback loops. #DevSecOps blog.gitguardian.com/dev-mtl-2025/
blog.gitguardian.com
Lessons in Testing, Performance, and Legacy Systems from /dev/mtl 2025
Montreal's recent community event revealed how feature flags, observability, and lifecycle discipline help teams manage complexity without compromising security or stability.
010
GitGuardian @gitguardian.com · 28/11/2025
🚨 #Shai_Hulud techincal analysis is live We've completed our forensic analysis of the Nov 24 supply chain attack. 754 infected npm packages, 20,649 analyzed repositories, 33,185 unique secrets (3,760 valid). blog.gitguardian.com/shai-hulud-2/
000
GitGuardian @gitguardian.com · 24/11/2025
🔐 The 2025 #OWASP Top 10 2025 says it loud: access control still #1, but now supply chains & mis‑configs steal the spotlight. Ready your CI/CD, stacks & cloud. blog.gitguardian.com/owasp-top-10... #AppSec #DevSecOps
blog.gitguardian.com
OWASP Top 10 2025 Updates: Supply Chain, Secrets, And Misconfigurations Take Center Stage
Discover what’s changed in the OWASP 2025 Top 10 and how GitGuardian helps you mitigate risks like broken access control and software supply chain failures.
010
GitGuardian @gitguardian.com · 21/11/2025
🔐 From “API keys in Git” to “agentic AI with scoped identities” — the next frontier of security is non‑human actors with strong attestation. #DevSecOps #CloudNative #CyberArk #SPIFFE #KubeCon blog.gitguardian.com/workload-ide...
blog.gitguardian.com
Workload And Agentic Identity at Scale: Insights From CyberArk's Workload Identity Day Zero
On the eve of KubeCon 2025, experts from companies like Uber, AWS, and Block shared how SPIRE and workload identity fabrics reduce risk in complex, cloud-native systems.
000
GitGuardian @gitguardian.com · 20/11/2025
Containers were the on‑ramp, not the destination.” At #KubeCon 2025 identity, governance & agent security stole the show. Microservices + AI = new risk surface. Read more: blog.gitguardian.com/kubecon-2025
blog.gitguardian.com
Trust Beyond Containers: Identity and Agent Security Lessons from KubeCon 2025
From secure service mesh rollouts to AI cluster hardening, see how KubeCon + CloudNativeCon NA 2025 redefined identity, trust, and governance in Kubernetes environments.
011
GitGuardian @gitguardian.com · 06/11/2025
🚨 Identity is the new perimeter. At #BSidesChicago 2025 we saw attackers moving through the cloud control‑plane like it’s tourist season — service principals & Kubernetes misconfigs are their playground. 🍿 Dive deeper: blog.gitguardian.com/bsides-chica... #DevSecOps #AppSec
blog.gitguardian.com
BSides Chicago 2025: Operationalizing Identity Risk In Cloud-Native Environments
Highlights from BSides Chicago 2025, where we explored cloud-native identity risks, from service principal abuse to Kubernetes misconfigs and control-plane compromise tactics.
000
GitGuardian @gitguardian.com · 04/11/2025
At #TechnoSecurity West 2025, identity = perimeter. If your IAM is a maze, attackers have already found the exit. 🧩🔐 blog.gitguardian.com/techno-secur...
blog.gitguardian.com
Identity Architecture Now Drives Cyber Risk: Techno Security & Digital Forensics Conference West 2025
Identity, classification, and cloud persistence risks took center stage at Techno Security West 2025. Learn what cybersecurity leaders are prioritizing now.
000
GitGuardian @gitguardian.com · 31/10/2025
Human admins aren’t the only VIPs; service accounts and automation scripts need the spotlight too. 👀 Read how GitGuardian helps you widen the scope of PAM and kill secret sprawl for good. blog.gitguardian.com/working-towa... #AppSec #SecOps
000
GitGuardian @gitguardian.com · 21/10/2025
🚀 At #INCYBERCanada 2025 in Montréal we heard loud & clear: compliance doesn’t cut it anymore—collaboration is the new security foundation. 🌐 Let’s govern machine identities, secure our global supply‑chains, and build resilience together. blog.gitguardian.com/incyber-foru...
blog.gitguardian.com
INCYBER Forum Canada 2025: Collaboration Wins Over Compliance
At INCYBER Forum Canada 2025, leaders from across sectors explored AI, supply-chain risk, and culture-driven defense, stressing that true resilience is built together.
000
GitGuardian @gitguardian.com · 21/10/2025
Back to security basics at CornCon 11: Why resilience beats perfection The big takeaway: Embrace sustainable security programmes – don’t chase zero‑risk illusions, build something you can maintain. Read more: blog.gitguardian.com/corncon-11/
blog.gitguardian.com
Rethinking Security Resilience And Getting Back To Basics At CornCon 11
CornCon 11 emphasized security basics, real-world risk alignment, and sustainable practices to help teams build resilient programs in today’s complex threat landscape.
010
GitGuardian @gitguardian.com · 03/10/2025
GitHub is doubling down: requiring WebAuthn, OIDC, and ultra-short tokens to harden npm publishing. These aren’t just npm rules — they’re lessons for all devs. 🔐 blog.gitguardian.com/security-les... #DevSecOps #SupplyChainSecurity
blog.gitguardian.com
Security Lessons For All From GitHub's Hardened Package Publication For npm
GitHub is hardening npm publishing rules but the underlying lessons can be applied by all developers: WebAuthn for writes, OIDC, and short-lived least-privilege credentials.
000
GitGuardian @gitguardian.com · 19/09/2025
Who owns your API keys? Spoiler: probably not the person you think 😅 Stop playing hot potato with NHIs—focus on context, not blame. 👉 blog.gitguardian.com/defining-nhi... #OWASP #NHIs #MachineIdentities
blog.gitguardian.com
Who Governs Your NHIs? The Challenge of Defining Ownership in Modern Enterprise IT
Learn how to shift the conversation from "who’s to blame" to "who has context" in managing non-human identities across modern enterprise IT infrastructure.
000
GitGuardian @gitguardian.com · 10/09/2025
BlueTeamCon 2025 taught us: perfection’s overrated; logs, pragmatic AI, and identity tweaks win. Who knew fixing cybersecurity could feel like adulting? 🕵️‍♂️🔍 Check it out: blog.gitguardian.com/blueteamcon-...
blog.gitguardian.com
BlueTeamCon 2025: Finding new approaches to security that don’t let perfect stand in the way of better
BlueTeamCon 2025 showed why progress beats perfection in cybersecurity. Explore highlights on visibility, AI safety, collaboration, identity, and pragmatic defense.
000
GitGuardian @gitguardian.com · 05/09/2025
🚨 𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚: 𝗚𝗶𝘁𝗚𝘂𝗮𝗿𝗱𝗶𝗮𝗻 𝗨𝗻𝗰𝗼𝘃𝗲𝗿𝘀 𝗠𝗮𝘀𝘀𝗶𝘃𝗲 𝗦𝘂𝗽𝗽𝗹𝘆 𝗖𝗵𝗮𝗶𝗻 𝗔𝘁𝘁𝗮𝗰𝗸 We've discovered a coordinated campaign we called "GhostAction", that compromised 817 #GitHub repositories across 327 users, 𝘀𝘁𝗲𝗮𝗹𝗶𝗻𝗴 𝟯,𝟯𝟮𝟱 𝘀𝗲𝗰𝗿𝗲𝘁𝘀 through malicious CI/CD workflows. blog.gitguardian.com/ghostaction-...
blog.gitguardian.com
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 repositories. Attackers injected malicious workflows that *exfiltrated 3,3...
021
GitGuardian @gitguardian.com · 04/09/2025
Overprivileged bots are the new insider threat 🤖💣 Most API tokens still have full access. Why? Because to many teams, breaking prod > breaking security. Time to rethink privilege and NHI governance. Full post 👉 blog.gitguardian.com/principle-of...
blog.gitguardian.com
Why the Principle of Least Privilege Is Critical for Non-Human Identities
Overprivileged non-human identities expose enterprises to massive risk. Enforcing least privilege with automation and visibility is critical for security.
000
GitGuardian @gitguardian.com · 03/09/2025
Following the recent breach, we've just published the complete playbook: how to build a #Salesforce secrets scanning pipeline using Salesforce CLI + GitGuardian's detection engine. Read our emergency response guide: lnkd.in/e78Jm586
000