Website: gitguardian.com
Blog: blog.gitguardian.com
Free GH audit: s.gitguardian.com/free-audit
Jan 27: Join GitGuardian at #NHIcon2026.
Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social
Free registration here: aembit.io/nhicon?aff=G...
Jan 27: Join GitGuardian at #NHIcon2026.
Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social
Free registration here: aembit.io/nhicon?aff=G...
Register to attend this event here:
👇
Register to attend this event here:
👇
blog.gitguardian.com/building-a-m...
The complete code is available at: github.com/reaandrew/a2...
blog.gitguardian.com/building-a-m...
The complete code is available at: github.com/reaandrew/a2...
AWS IAM Outbound Identity Federation eliminates long‑term creds in favor of short‑lived tokens.
GitGuardian can help you track the migration in real time.
blog.gitguardian.com/aws-iam-outb...
#DevSecOps #AppSec
AWS IAM Outbound Identity Federation eliminates long‑term creds in favor of short‑lived tokens.
GitGuardian can help you track the migration in real time.
blog.gitguardian.com/aws-iam-outb...
#DevSecOps #AppSec
GitGuardian's Push-to-Vault turns “uh-oh” into “handled” by sending secrets straight into your existing Secret Manager.
No more tab juggling.
blog.gitguardian.com/push-to-vault/
GitGuardian's Push-to-Vault turns “uh-oh” into “handled” by sending secrets straight into your existing Secret Manager.
No more tab juggling.
blog.gitguardian.com/push-to-vault/
#DevSecOps
blog.gitguardian.com/dev-mtl-2025/
#DevSecOps
blog.gitguardian.com/dev-mtl-2025/
We've completed our forensic analysis of the Nov 24 supply chain attack. 754 infected npm packages, 20,649 analyzed repositories, 33,185 unique secrets (3,760 valid).
blog.gitguardian.com/shai-hulud-2/
We've completed our forensic analysis of the Nov 24 supply chain attack. 754 infected npm packages, 20,649 analyzed repositories, 33,185 unique secrets (3,760 valid).
blog.gitguardian.com/shai-hulud-2/
access control still #1, but now supply chains & mis‑configs steal the spotlight.
Ready your CI/CD, stacks & cloud.
blog.gitguardian.com/owasp-top-10...
#AppSec #DevSecOps
access control still #1, but now supply chains & mis‑configs steal the spotlight.
Ready your CI/CD, stacks & cloud.
blog.gitguardian.com/owasp-top-10...
#AppSec #DevSecOps
#KubeCon
blog.gitguardian.com/workload-ide...
#KubeCon
blog.gitguardian.com/workload-ide...
Read more: blog.gitguardian.com/kubecon-2025
Read more: blog.gitguardian.com/kubecon-2025
blog.gitguardian.com/bsides-chica...
#DevSecOps #AppSec
blog.gitguardian.com/bsides-chica...
#DevSecOps #AppSec
If your IAM is a maze, attackers have already found the exit.
🧩🔐
blog.gitguardian.com/techno-secur...
If your IAM is a maze, attackers have already found the exit.
🧩🔐
blog.gitguardian.com/techno-secur...
👀
Read how GitGuardian helps you widen the scope of PAM and kill secret sprawl for good.
blog.gitguardian.com/working-towa...
#AppSec #SecOps
👀
Read how GitGuardian helps you widen the scope of PAM and kill secret sprawl for good.
blog.gitguardian.com/working-towa...
#AppSec #SecOps
blog.gitguardian.com/incyber-foru...
blog.gitguardian.com/incyber-foru...
The big takeaway:
Embrace sustainable security programmes – don’t chase zero‑risk illusions, build something you can maintain.
Read more: blog.gitguardian.com/corncon-11/
The big takeaway:
Embrace sustainable security programmes – don’t chase zero‑risk illusions, build something you can maintain.
Read more: blog.gitguardian.com/corncon-11/
blog.gitguardian.com/security-les...
#DevSecOps #SupplyChainSecurity
blog.gitguardian.com/security-les...
#DevSecOps #SupplyChainSecurity
Spoiler: probably not the person you think
😅 Stop playing hot potato with NHIs—focus on context, not blame.
👉 blog.gitguardian.com/defining-nhi...
#OWASP #NHIs #MachineIdentities
Spoiler: probably not the person you think
😅 Stop playing hot potato with NHIs—focus on context, not blame.
👉 blog.gitguardian.com/defining-nhi...
#OWASP #NHIs #MachineIdentities
🕵️♂️🔍
Check it out: blog.gitguardian.com/blueteamcon-...
🕵️♂️🔍
Check it out: blog.gitguardian.com/blueteamcon-...
We've discovered a coordinated campaign we called "GhostAction", that compromised 817 #GitHub repositories across 327 users, 𝘀𝘁𝗲𝗮𝗹𝗶𝗻𝗴 𝟯,𝟯𝟮𝟱 𝘀𝗲𝗰𝗿𝗲𝘁𝘀 through malicious CI/CD workflows.
blog.gitguardian.com/ghostaction-...
We've discovered a coordinated campaign we called "GhostAction", that compromised 817 #GitHub repositories across 327 users, 𝘀𝘁𝗲𝗮𝗹𝗶𝗻𝗴 𝟯,𝟯𝟮𝟱 𝘀𝗲𝗰𝗿𝗲𝘁𝘀 through malicious CI/CD workflows.
blog.gitguardian.com/ghostaction-...
Most API tokens still have full access.
Why?
Because to many teams, breaking prod > breaking security.
Time to rethink privilege and NHI governance.
Full post 👉
blog.gitguardian.com/principle-of...
Most API tokens still have full access.
Why?
Because to many teams, breaking prod > breaking security.
Time to rethink privilege and NHI governance.
Full post 👉
blog.gitguardian.com/principle-of...
Read our emergency response guide: lnkd.in/e78Jm586
Read our emergency response guide: lnkd.in/e78Jm586
Hear from GitGuardian's Cybersecurity Researcher on what he discovered when he dug into the recent Nx "s1ngularity" attack, affecting thousands of users.
youtu.be/t3RSKws0en4
#Nx #s1ngularity #DevSecOps #SupplyChainAttack
Hear from GitGuardian's Cybersecurity Researcher on what he discovered when he dug into the recent Nx "s1ngularity" attack, affecting thousands of users.
youtu.be/t3RSKws0en4
#Nx #s1ngularity #DevSecOps #SupplyChainAttack
Explore our advancements in secrets security across code, collaboration tools, and public repos. Dive into new Agentic #AI protection, #NHI lifecycle automation.
blog.gitguardian.com/q2-2025-reca...
Explore our advancements in secrets security across code, collaboration tools, and public repos. Dive into new Agentic #AI protection, #NHI lifecycle automation.
blog.gitguardian.com/q2-2025-reca...
blog.gitguardian.com/from-secrets...
blog.gitguardian.com/from-secrets...
Your #AI agents can now handle secrets security directly in your workflow:
• "Scan this code for leaked secrets"
• "Remediate all my project incidents"
• "Generate AWS honeytoken"
500+ secret types detected. Zero context switching.
Code: github.com/GitGuardian/gg-mcp
Your #AI agents can now handle secrets security directly in your workflow:
• "Scan this code for leaked secrets"
• "Remediate all my project incidents"
• "Generate AWS honeytoken"
500+ secret types detected. Zero context switching.
Code: github.com/GitGuardian/gg-mcp