Sign in

Dwayne McDaniel

@mdwayne-real.bsky.social
274 followers 271 following 1.1K posts

I help people figure stuff out. I work at gitguardian.com Also, I am at www.linkedin.com/in/dwaynemcdaniel

PostsRepliesMedia
Dwayne McDaniel @mdwayne-real.bsky.social · 4h
If you have talked to me in person at all in the last 3 weeks, you already know I can not stop talking about "deterministic controls" around AI workflow. TL;DR: Install ggshield AI hooks right now and stop agents from abusing secrets they find. blog.gitguardian.com/ai-hooks-ai-...
blog.gitguardian.com
AI Hooks for Claude Code, Cursor, and Codex: Block Secrets
AI coding assistants are unpredictable by design. Learn how AI hooks add deterministic controls and how GitGuardian ggshield blocks secrets before agents can use them.
000
Dwayne McDaniel @mdwayne-real.bsky.social · 7h
Always an honor to see my work on #TheHackerNews This is the first of 3 I am getting to write over the rest of 2026 :) thehackernews.com/2026/10/the-...
000
Dwayne McDaniel @mdwayne-real.bsky.social · 07/10/2026
For months, I have been telling everyone who will listen to go read the Uber paper on how they handle agentic access at scale as my favorite paper on the subject. It has a strong contender now for favorite, but I will be recommending both moving ahead: blog.postman.com/credential-s...
blog.postman.com
Enterprises: Stop Handing Out API Keys! (How Postman Ended Credential Sprawl with Passport)
See how Postman used its own Passport product to kill credential sprawl, govern API access for AI agents, and cut new engineer onboarding from weeks to hours.
010
Dwayne McDaniel @mdwayne-real.bsky.social · 07/10/2026
Today, there was a discussion of trusting open-weight models, as anyone training them can hide possible malicious things in them. This is not a new problem. Sharing this since I looked it up already www.cs.cmu.edu/~rdriley/487...
000
Dwayne McDaniel @mdwayne-real.bsky.social · 06/10/2026
This is a very encouraging story, I think. New features don't keep you safe. Fixing the glaring security holes in your platform helps you retain customers. techcrunch.com/2026/10/02/m...
techcrunch.com
Medical records giant Epic pauses product development to fix security bugs that risk patients' data | TechCrunch
The health tech software giant, which makes the widely used MyChart system for accessing medical data, will focus on fixing security bugs for the next few weeks.
000
Dwayne McDaniel @mdwayne-real.bsky.social · 06/10/2026
I did my best to boil it up a level and really look at the business benefits that security leaders can use in their conversations about measuring their secrets security programs blog.gitguardian.com/secrets-mana...
blog.gitguardian.com
Secrets Management Best Practices: Vault vs. Detector
A secrets vault controls the credentials you manage. Detection finds the ones that escaped. Here are six reasons mature secrets management programs need both.
000
Dwayne McDaniel @mdwayne-real.bsky.social · 04/10/2026
#CornCon 2026 was the best one yet. 445 individual people came to Davenport, but we left as 1 connected community. I learned so much. Here is my blog wrap-up of the event (AI-assisted from my typed notes) dwayne-mcdaniel.com/blog/CornCon...
000
Dwayne McDaniel @mdwayne-real.bsky.social · 04/10/2026
#CornCon 2026 Closing Keynote: From security program building to vulnerability research: our narratives and being AI native from Gadi Evron
000
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 US Cyber Strategy: More Lessons and Lessons from John Aron
000
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 From Secure-by-Design to Abuse-by-Design: Why Modern Systems Fail in Ways We Don’t Model from Swati Babbar and Arjun Katneni
000
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 From Cognitive Surrender to Cognitive Pearl Harbor Winn Schwartau
010
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 Cybersecurity – The Big Pharma of Tech: Why Zero Trust is the Real Cure Louis DeWeaver
010
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 [Panel] AI Governance Without Handcuffs: Enabling Innovation While Managing Risk with Bruce Phillips Fred Kwong Bob Flores and Richard Greenberg
010
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
#CornCon 2026 CISO Panel with Walter Lefmann Rob Labbe Laszlo Gonc
010
Dwayne McDaniel @mdwayne-real.bsky.social · 03/10/2026
CornCon 2026 Day 2 opening keynote: Compliance Equals Security from Jeff Man
010
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 day 1 closing keynote Threat Intelligence Isn’t a Feed: Using It to Drive Security Decisions and Calm the Chaos Monkeys from Corey Hlavacek
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Auditing AI in Practice: From Risk to Evidence from Michael Ratemo
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
From Click Ops to Closed Loop: Rotating 1000+ Database Credentials Without an Outage from Mayank Sethi
010
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Who Governs the Agents? The Human Governance Gap in Cybersecurity and AI from John Kwarsick
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Finding Bugs Is Easy, Patching Isn't: Build Your Own Remediation Pipeline from Mohankumar Vengatachalam of Aria Security
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 The Army Of The 12 Million Chaos Monkeys On Life-Safety Critical Infrastructure from Joshua Corman and David Etue
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Securing What Feeds Us: How Cyber Risk Reaches the Modern Farm from Kristin King
000
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Why Nobody Trusts Us from the one and only Robert Wagner
010
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
#CornCon 2026 Keynote: Attack Vectors & AI: How to make your business a Hard Target from JD Eger of ThreatLocker
010
Dwayne McDaniel @mdwayne-real.bsky.social · 02/10/2026
One of my all-time favorite conferences has kicked off the 2026 edition! #CornCon is here!!! This schedule looks amazing, as always corncon.net
000
Dwayne McDaniel @mdwayne-real.bsky.social · 01/10/2026
Did I mention I was proud of our partnership with Docker Sandboxes yet? Here is what they look like in action: youtu.be/TykevwaEHK0
youtu.be
Introducing The GitGuardian Mixin Kit To Extend Docker Sandboxes for Safer AI Coding
Modern enterprise security is increasingly being tasked with keeping agents from affecting critical data and infrastructure. In this video, Dwayne, principal developer at GitGuardian, introduces how…
020
Dwayne McDaniel @mdwayne-real.bsky.social · 01/10/2026
The original use case that #GitGuardian was built on is monitoring public GitHub for leaked secrets. We have continued to evolve this capability, including how we "identity stitch" to connect personal public repos to real customers' production credentials. blog.gitguardian.com/public-monit...
blog.gitguardian.com
GitGuardian Agents Analysis: Know If A Leak Is Yours
GitGuardian found a public GitHub repo tied to CISA leaking 844MB of live credentials. Agents Analysis flags which public leaks are actually yours.
010
Dwayne McDaniel @mdwayne-real.bsky.social · 30/09/2026
Have you heard of Dogwood yet? It answers a very specific need around agentic security that I don't hear a lot of people talking about yet. blog.gitguardian.com/a-look-at-aw...
blog.gitguardian.com
AWS Dogwood: AI Agent Authorization Beyond Authentication
AWS Dogwood brings stateful authorization to AI agents. Learn how it fits with workload identity, AuthZEN, IAM, and the move away from long-lived credentials.
021
Dwayne McDaniel @mdwayne-real.bsky.social · 28/09/2026
Over the weekend, I was fortunate enough to be part of #BSidesCLE 2026 I had an amazing time with this great community in my birth state of Ohio. Here are some notes I was able to take: dwayne-mcdaniel.com/blog/BSidesC...
dwayne-mcdaniel.com
BSides Cleveland 2026: Reducing the Paths Attackers Can Use
Recap of BSides Cleveland 2026's Blue Team track: ghost admins, AI governance, supply chain pruning, inductive compliance, zero-trust CI/CD, and AI in the SOC.
100
Dwayne McDaniel @mdwayne-real.bsky.social · 27/09/2026
This past week, I got the chance to be part of the very first WeAreDevelopers World Congress North America I learned SO MUCH!!! Thanks to #Docker for hosting me on their stage to talk about their new sandbox kits. dwayne-mcdaniel.com/blog/WeAreDe...
dwayne-mcdaniel.com
WeAreDevelopers World Congress North America 2026: Trust Moves Into the System
Recap of WeAreDevelopers World Congress North America 2026 in San José: agent sandboxes, supply chain security, zero trust agents, independent verification, and authorization as infrastructure.
100
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 The SOC Intern That Never Sleeps: Lessons Learned Using AI for Security Operations Michael Blanchard
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 Zero-Trust CI/CD: Securing Kubernetes and GitOps Pipelines for Regulated Enterprises Shashi Kumar Munugoti
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 Inductive Compliance: Lightweight & Noninvasive Transition-Gating for Declarative Infrastruce Kavin Muthuselvan
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 Hardening Supply Chain Security by Pruning JavaScript Dependencies Jim Ender
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 The Common Sense Security Framework: Revisited and Revised from Jerod Brennen
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
#BSidesCLE 2026 Positive Intent Is Not a Control from Elizabeth Wadsworth
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
First session at #BSidesCLE 2026 Ghost Admins: How Attackers Own Environments Without Touching a User From Craig Birch
000
Dwayne McDaniel @mdwayne-real.bsky.social · 26/09/2026
BSides Cleveland 2026 has officially kicked off!!!! #BSidesCLE 2026
010
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
I will not be providing context
000
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
Merge for Docker Sandboxed Agents · from Gil Feig of Merge, on the Docker Pavilion stage #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
Guardrails Inside the Docker Sandbox: Securing Agentic Applications at Runtime · with Gary Segal from Mend.io on the Docker Pavilion stage #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
From Guesswork to Governance: Data Contracts Bring API Discipline to Apache Kafka with Sandon Jacobs #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
It passed auth, then production caught fire with Alex Olivier at #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 25/09/2026
Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026 with Farshad Abasi from Forward Security at #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
The reviewer can't be the author: independent verification for AI-generated code with Manish Kapur #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
Two Gates of Defense: Running AI Agents Safely with Docker Sandbox and Prediction Guard with Sharan Shirocdkar on the Docker Pavilion stage #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
Know Your Enemies: Live Exploit of a PHP Engine Security Breach with Alexandre Daubois #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
The New Security Stack with Sagi Rodin & Andrea Muttoni & James Everingham & Kara Sprague & Javier Garza #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
Hardening the Whale: ClickHouse on Docker Hardened Images from ClickHouse on the Docker Pavilion stage #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
000
Dwayne McDaniel @mdwayne-real.bsky.social · 24/09/2026
Securing Autonomous AI Agents, from Detection to Resolution · with Amrita Lakhanpal Datadog on the Docker Pavilion stage #WeAreDevelopers #WorldCongress #NorthAmerica 2026 #WADWCNA 2026
010