Install
A blog for developers, Application Security and other cybersecurity professionals to learn about secrets in source code, API security, IaC and DevSecOps.
- 7articles · 30d
- 5+ day agolatest article
- Aug 18, 2026earliest in window
- 86%with images
- 389avg words
- Computers & Electronics 7
- Science & Technology 7
- Software Dev. 7
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Credential Rotation Blast Radius: 8 Questions Checklist
5+ day, 22+ hour ago (1659+ words) GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and has been involved in the wider tech community since 2005. He is on a mission to help people figure stuff out. More posts by Dwayne McDaniel. Every…...
OWASP Top 10 CI/CD Security Risks Explained
1+ week, 4+ day ago (1465+ words) Learn how the OWASP Top 10 CI/CD Security Risks map the modern software delivery attack surface, and why credential hygiene sits at the center of so many real-world failures. GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations…...
Credential Security vs EDR: What Actually Protects Secrets
1+ week, 5+ day ago (1527+ words) Antivirus and EDR catch malicious behavior on a machine. Neither tells you which valid credentials are exposed on it right now. That's credential security, a distinct job that finds exposed secrets and helps fix them before attackers do. This article…...
Agentic AI Security Comes Down to Access, Not the Trick
2+ week, 5+ day ago (431+ words) Katie DeMatteis is Director of Content and Brand at GitGuardian, where she leads content strategy and brand storytelling across secrets security, credential exposure, developer security, and non-human identity risk. More posts by Katie DeMatteis. Three disclosures from 2026 make the pattern…...
ChainDrop npm Worm: AI Agents And Credential Abuse
3+ week, 3+ day ago (1581+ words) ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse GitGuardian Developer Advocate - Dwayne has been working as a Developer Relations professional since 2016 and has been involved…...
Credential Exposure and the Security Stack Gap
3+ week, 6+ day ago (830+ words) Your security stack is a set of specialists, each guarding one territory. Exposed credentials don't respect the boundaries between them, and 64% of the ones found valid in 2022 were still valid four years later. Katie DeMatteis is Director of Content and…...