GitGuardian
banner
gitguardian.com
GitGuardian
@gitguardian.com
GitGuardian leads the way in Non-Human Identity security, offering end-to-end solutions.

Website: gitguardian.com
Blog: blog.gitguardian.com
Free GH audit: s.gitguardian.com/free-audit
AI agents are already causing incidents, and identity controls aren’t ready.

Jan 27: Join GitGuardian at #NHIcon2026.

Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social

Free registration here: aembit.io/nhicon?aff=G...
NHIcon 2026 by Aembit | Jan. 27
Agentic software is moving fast. NHIcon 2026 is one-day virtual experience for platform and security pros tackling AI and non-human identity challenges.
aembit.io
January 7, 2026 at 5:14 PM
Reposted by GitGuardian
The next OWASP London Chapter in-person Meetup will take place on January 21st, 2026, kindly sponsored by @nuaware_tech with raffle prizes kindly sponsored by @GitGuardian and @Docker

Register to attend this event here:
👇
OWASP London Chapter Meetup [IN-PERSON], Wed, Jan 21, 2026, 6:00 PM | Meetup
**This event is kindly sponsored by Nuaware.** **Raffle prizes are kindly sponsored by GitGuardian and Docker.** **There is limited seating available for in-person attende
www.meetup.com
January 7, 2026 at 12:37 PM
Andy Rea built a demo showing how to wire up multiple AI agents using Google's Agent Development Kit (ADK) and the #A2A protocol, with GitGuardian scanning content for secrets.
blog.gitguardian.com/building-a-m...

The complete code is available at: github.com/reaandrew/a2...
December 19, 2025 at 9:29 AM
🚀 The future of secure non‑human identity is here!

AWS IAM Outbound Identity Federation eliminates long‑term creds in favor of short‑lived tokens.

GitGuardian can help you track the migration in real time.

blog.gitguardian.com/aws-iam-outb...

#DevSecOps #AppSec
Getting To AWS IAM Outbound Identity Federation With GitGuardian
Secure all your non-human identities across providers and without secrets. Explore how AWS and GitGuardian can help organizations migrate to short-lived tokens.
blog.gitguardian.com
December 17, 2025 at 3:21 PM
Secrets leaked? Don’t panic—push to vault! 🧯
GitGuardian's Push-to-Vault turns “uh-oh” into “handled” by sending secrets straight into your existing Secret Manager.
No more tab juggling.
blog.gitguardian.com/push-to-vault/
From Detection to Defense: How Push-to-Vault Supercharges Secrets Management for DevSecOps
Secrets don’t belong in plaintext. GitGuardian's Push-to-Vault automates vaulting exposed secrets, helping security teams scale governance and reduce incident fatigue.
blog.gitguardian.com
December 5, 2025 at 3:41 PM
🔄 Feature flags, legacy systems, and N+1 queries walk into a dev conf... /dev/mtl 2025 reminds us: it’s not about speed, it’s about smart feedback loops.
#DevSecOps
blog.gitguardian.com/dev-mtl-2025/
Lessons in Testing, Performance, and Legacy Systems from /dev/mtl 2025
Montreal's recent community event revealed how feature flags, observability, and lifecycle discipline help teams manage complexity without compromising security or stability.
blog.gitguardian.com
December 3, 2025 at 4:34 PM
🚨 #Shai_Hulud techincal analysis is live
We've completed our forensic analysis of the Nov 24 supply chain attack. 754 infected npm packages, 20,649 analyzed repositories, 33,185 unique secrets (3,760 valid).
blog.gitguardian.com/shai-hulud-2/
November 28, 2025 at 12:18 PM
🔐 The 2025 #OWASP Top 10 2025 says it loud:
access control still #1, but now supply chains & mis‑configs steal the spotlight.
Ready your CI/CD, stacks & cloud.

blog.gitguardian.com/owasp-top-10...

#AppSec #DevSecOps
OWASP Top 10 2025 Updates: Supply Chain, Secrets, And Misconfigurations Take Center Stage
Discover what’s changed in the OWASP 2025 Top 10 and how GitGuardian helps you mitigate risks like broken access control and software supply chain failures.
blog.gitguardian.com
November 24, 2025 at 3:10 PM
🔐 From “API keys in Git” to “agentic AI with scoped identities” — the next frontier of security is non‑human actors with strong attestation. #DevSecOps #CloudNative #CyberArk #SPIFFE
#KubeCon

blog.gitguardian.com/workload-ide...
Workload And Agentic Identity at Scale: Insights From CyberArk's Workload Identity Day Zero
On the eve of KubeCon 2025, experts from companies like Uber, AWS, and Block shared how SPIRE and workload identity fabrics reduce risk in complex, cloud-native systems.
blog.gitguardian.com
November 21, 2025 at 3:19 PM
Containers were the on‑ramp, not the destination.” At #KubeCon 2025 identity, governance & agent security stole the show. Microservices + AI = new risk surface.
Read more: blog.gitguardian.com/kubecon-2025
Trust Beyond Containers: Identity and Agent Security Lessons from KubeCon 2025
From secure service mesh rollouts to AI cluster hardening, see how KubeCon + CloudNativeCon NA 2025 redefined identity, trust, and governance in Kubernetes environments.
blog.gitguardian.com
November 20, 2025 at 3:27 PM
🚨 Identity is the new perimeter. At #BSidesChicago 2025 we saw attackers moving through the cloud control‑plane like it’s tourist season — service principals & Kubernetes misconfigs are their playground. 🍿 Dive deeper:
blog.gitguardian.com/bsides-chica...

#DevSecOps #AppSec
BSides Chicago 2025: Operationalizing Identity Risk In Cloud-Native Environments
Highlights from BSides Chicago 2025, where we explored cloud-native identity risks, from service principal abuse to Kubernetes misconfigs and control-plane compromise tactics.
blog.gitguardian.com
November 6, 2025 at 3:33 PM
At #TechnoSecurity West 2025, identity = perimeter.
If your IAM is a maze, attackers have already found the exit.
🧩🔐
blog.gitguardian.com/techno-secur...
Identity Architecture Now Drives Cyber Risk: Techno Security & Digital Forensics Conference West 2025
Identity, classification, and cloud persistence risks took center stage at Techno Security West 2025. Learn what cybersecurity leaders are prioritizing now.
blog.gitguardian.com
November 4, 2025 at 3:28 PM
Human admins aren’t the only VIPs; service accounts and automation scripts need the spotlight too.

👀

Read how GitGuardian helps you widen the scope of PAM and kill secret sprawl for good.

blog.gitguardian.com/working-towa...

#AppSec #SecOps
October 31, 2025 at 4:09 PM
🚀 At #INCYBERCanada 2025 in Montréal we heard loud & clear: compliance doesn’t cut it anymore—collaboration is the new security foundation. 🌐 Let’s govern machine identities, secure our global supply‑chains, and build resilience together.

blog.gitguardian.com/incyber-foru...
INCYBER Forum Canada 2025: Collaboration Wins Over Compliance
At INCYBER Forum Canada 2025, leaders from across sectors explored AI, supply-chain risk, and culture-driven defense, stressing that true resilience is built together.
blog.gitguardian.com
October 21, 2025 at 2:11 PM
Back to security basics at CornCon 11: Why resilience beats perfection

The big takeaway:
Embrace sustainable security programmes – don’t chase zero‑risk illusions, build something you can maintain.

Read more: blog.gitguardian.com/corncon-11/
Rethinking Security Resilience And Getting Back To Basics At CornCon 11
CornCon 11 emphasized security basics, real-world risk alignment, and sustainable practices to help teams build resilient programs in today’s complex threat landscape.
blog.gitguardian.com
October 21, 2025 at 1:21 PM
GitHub is doubling down: requiring WebAuthn, OIDC, and ultra-short tokens to harden npm publishing. These aren’t just npm rules — they’re lessons for all devs. 🔐

blog.gitguardian.com/security-les...

#DevSecOps #SupplyChainSecurity
Security Lessons For All From GitHub's Hardened Package Publication For npm
GitHub is hardening npm publishing rules but the underlying lessons can be applied by all developers: WebAuthn for writes, OIDC, and short-lived least-privilege credentials.
blog.gitguardian.com
October 3, 2025 at 4:26 PM
Who owns your API keys?
Spoiler: probably not the person you think

😅 Stop playing hot potato with NHIs—focus on context, not blame.
👉 blog.gitguardian.com/defining-nhi...

#OWASP #NHIs #MachineIdentities
Who Governs Your NHIs? The Challenge of Defining Ownership in Modern Enterprise IT
Learn how to shift the conversation from "who’s to blame" to "who has context" in managing non-human identities across modern enterprise IT infrastructure.
blog.gitguardian.com
September 19, 2025 at 2:08 PM
BlueTeamCon 2025 taught us: perfection’s overrated; logs, pragmatic AI, and identity tweaks win. Who knew fixing cybersecurity could feel like adulting?
🕵️‍♂️🔍

Check it out: blog.gitguardian.com/blueteamcon-...
BlueTeamCon 2025: Finding new approaches to security that don’t let perfect stand in the way of better
BlueTeamCon 2025 showed why progress beats perfection in cybersecurity. Explore highlights on visibility, AI safety, collaboration, identity, and pragmatic defense.
blog.gitguardian.com
September 10, 2025 at 3:08 PM
🚨 𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚: 𝗚𝗶𝘁𝗚𝘂𝗮𝗿𝗱𝗶𝗮𝗻 𝗨𝗻𝗰𝗼𝘃𝗲𝗿𝘀 𝗠𝗮𝘀𝘀𝗶𝘃𝗲 𝗦𝘂𝗽𝗽𝗹𝘆 𝗖𝗵𝗮𝗶𝗻 𝗔𝘁𝘁𝗮𝗰𝗸
We've discovered a coordinated campaign we called "GhostAction", that compromised 817 #GitHub repositories across 327 users, 𝘀𝘁𝗲𝗮𝗹𝗶𝗻𝗴 𝟯,𝟯𝟮𝟱 𝘀𝗲𝗰𝗿𝗲𝘁𝘀 through malicious CI/CD workflows.
blog.gitguardian.com/ghostaction-...
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 repositories. Attackers injected malicious workflows that *exfiltrated 3,3...
blog.gitguardian.com
September 5, 2025 at 3:37 PM
Overprivileged bots are the new insider threat 🤖💣

Most API tokens still have full access.
Why?

Because to many teams, breaking prod > breaking security.

Time to rethink privilege and NHI governance.

Full post 👉
blog.gitguardian.com/principle-of...
Why the Principle of Least Privilege Is Critical for Non-Human Identities
Overprivileged non-human identities expose enterprises to massive risk. Enforcing least privilege with automation and visibility is critical for security.
blog.gitguardian.com
September 4, 2025 at 2:15 PM
Following the recent breach, we've just published the complete playbook: how to build a #Salesforce secrets scanning pipeline using Salesforce CLI + GitGuardian's detection engine.
Read our emergency response guide: lnkd.in/e78Jm586
September 3, 2025 at 3:06 PM
Heads up Nx users, your credentials might have been leaked.

Hear from GitGuardian's Cybersecurity Researcher on what he discovered when he dug into the recent Nx "s1ngularity" attack, affecting thousands of users.

youtu.be/t3RSKws0en4

#Nx #s1ngularity #DevSecOps #SupplyChainAttack
Investigating The Nx "s1ngularity" Attack: What GitGuardian Uncovered And How You Can Stay Safe
YouTube video by GitGuardian
youtu.be
August 28, 2025 at 6:38 PM
𝗤𝟮 𝟮𝟬𝟮𝟱 𝗣𝗿𝗼𝗱𝘂𝗰𝘁 𝗥𝗲𝗰𝗮𝗽: 𝗚𝗶𝘁𝗚𝘂𝗮𝗿𝗱𝗶𝗮𝗻 𝗦𝗵𝗮𝗿𝗽𝗲𝗻𝘀 𝘁𝗵𝗲 𝗘𝗱𝗴𝗲 𝗼𝗻 #𝗦𝗲𝗰𝗿𝗲𝘁𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 & 𝗔𝗴𝗲𝗻𝘁𝗶𝗰 𝗔𝗜 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻!

Explore our advancements in secrets security across code, collaboration tools, and public repos. Dive into new Agentic #AI protection, #NHI lifecycle automation.

blog.gitguardian.com/q2-2025-reca...
July 28, 2025 at 9:20 AM
Learn how Snowflake saved 10 hours per day for DevOps teams who were previously drowning in secret rotation hell, and remediated 50% of discovered secrets already. Insights from #SecDays {Virtual}
blog.gitguardian.com/from-secrets...
From Secrets Sprawl to Secretless: Snowflake's Journey through NHI Lifecycle Management
Learn how Snowflake is tackling NHIs, from secrets sprawl to a secretless architecture using GitGuardian for detection and Aembit for prevention.
blog.gitguardian.com
July 25, 2025 at 7:45 AM
🚀 Introducing our #MCP Server!
Your #AI agents can now handle secrets security directly in your workflow:
• "Scan this code for leaked secrets"
• "Remediate all my project incidents"
• "Generate AWS honeytoken"
500+ secret types detected. Zero context switching.
Code: github.com/GitGuardian/gg-mcp
July 16, 2025 at 4:02 PM