GitGuardian's Avatar

GitGuardian

@gitguardian.com.bsky.social

GitGuardian leads the way in Non-Human Identity security, offering end-to-end solutions. Website: gitguardian.com Blog: blog.gitguardian.com Free GH audit: s.gitguardian.com/free-audit

195 Followers  |  123 Following  |  44 Posts  |  Joined: 14.09.2023  |  1.8588

Latest posts by gitguardian.com on Bluesky

Post image

๐—ค๐Ÿฎ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—ฃ๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐˜ ๐—ฅ๐—ฒ๐—ฐ๐—ฎ๐—ฝ: ๐—š๐—ถ๐˜๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ๐—ถ๐—ฎ๐—ป ๐—ฆ๐—ต๐—ฎ๐—ฟ๐—ฝ๐—ฒ๐—ป๐˜€ ๐˜๐—ต๐—ฒ ๐—˜๐—ฑ๐—ด๐—ฒ ๐—ผ๐—ป #๐—ฆ๐—ฒ๐—ฐ๐—ฟ๐—ฒ๐˜๐˜€ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† & ๐—”๐—ด๐—ฒ๐—ป๐˜๐—ถ๐—ฐ ๐—”๐—œ ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป!

Explore our advancements in secrets security across code, collaboration tools, and public repos. Dive into new Agentic #AI protection, #NHI lifecycle automation.

blog.gitguardian.com/q2-2025-reca...

28.07.2025 09:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
From Secrets Sprawl to Secretless: Snowflake's Journey through NHI Lifecycle Management Learn how Snowflake is tackling NHIs, from secrets sprawl to a secretless architecture using GitGuardian for detection and Aembit for prevention.

Learn how Snowflake saved 10 hours per day for DevOps teams who were previously drowning in secret rotation hell, and remediated 50% of discovered secrets already. Insights from #SecDays {Virtual}
blog.gitguardian.com/from-secrets...

25.07.2025 07:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitGuardian Launches its MCP Server: Putting Secrets Security in the Developers' Hands Empower your developers with GitGuardian's new MCP Server. Embed AI-driven secrets security directly into your IDE, streamline incident remediation, and secure code in real time.

Story: blog.gitguardian.com/gitguardian-launches-its-mcp-server-putting-secrets-security-in-the-developers-hands/

16.07.2025 16:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitGuardian MCP Server

GitGuardian MCP Server

๐Ÿš€ Introducing our #MCP Server!
Your #AI agents can now handle secrets security directly in your workflow:
โ€ข "Scan this code for leaked secrets"
โ€ข "Remediate all my project incidents"
โ€ข "Generate AWS honeytoken"
500+ secret types detected. Zero context switching.
Code: github.com/GitGuardian/gg-mcp

16.07.2025 16:02 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Operationalizing the OWASP AI Testing Guide with GitGuardian: Building Secure AI Foundations Through NHI Governance Align your AI pipelines with OWASP AI Testing principles using GitGuardianโ€™s identity-based insights to monitor, enforce, and audit secrets and token usage.

๐ŸŽญ Donโ€™t let your CI bots do the tango with secretsโ€”OWASPโ€™s AI Testing Guide + GitGuardianโ€™s NHI secret-police = least privilege enforcement in every pipeline! ๐Ÿ›ก๏ธ

blog.gitguardian.com/owasp-ai-tes...

26.06.2025 16:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SecDays Virtual 2025 ๐Ÿš€ | LinkedIn Join us for GitGuardian SecDays Virtual 2025 โ€“ a global event dedicated to securing Non-human Identities and their secrets in the age of AI agents. This year, we're bringing together the industry le...

We're live! ๐Ÿคฉ Join our SecDays {Virtual} event right now as we're discussing the expanding non-human identities attack surface: lnkd.in/e_NqGttp

26.06.2025 12:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

โœ๏ธ Meet our new blog author, Andy Rea! In his latest piece, โ€œAutomated Guard Rails for Vibe Coding,โ€ Andy shares how automation can let teams code with confidenceโ€”without losing sight of security or compliance blog.gitguardian.com/automated-gu...

#vibecoding #aiguardrails

19.06.2025 10:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Role of AI and Compliance in Modern Risk Management: ShowMeCon 2025 The speakers at ShowMeCon 2025 explored why policy isn't protection without validation. AI, identity, and threat detection must align to reduce operational risk.

๐Ÿงฑ Compliance builds the scaffold, but AIโ€‘powered checks & human brains build the fortress. Heard at #ShowMeCon 2025: policy + AI + validation = real risk reduction. ๐Ÿ›ก๏ธ

blog.gitguardian.com/showmecon-20...

18.06.2025 15:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Identiverse 2025: Trust, Delegation, and the Era of Continuous Identity Identiverse 2025 exposed the urgent need for NHI governance. From AI agents to orphaned credentials, NHIs and their sprawling secrets are todayโ€™s most overlooked risks.

Your secrets donโ€™t care who leaked themโ€”human or bot. ๐Ÿค– #Identiverse2025 showed why NHIs are todayโ€™s identity crisis. From agentic AI to orphaned creds, governance canโ€™t wait. Read our recap:

blog.gitguardian.com/identiverse-...

14.06.2025 01:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security Isnโ€™t A Solo Sport: Community, Burnout, and Identity at BSides312 At BSides312 in Chicago, experts showed that defending systems requires defending people, with trust, inclusion, and communication as key controls. Defense is deeply human.

Missed #BSides312? Our own @mdwayne-real.bsky.social was there and captured all the highlights! Reading his recap is like attending the event yourself. ๐Ÿ‘‰ blog.gitguardian.com/bsides312-20...

05.06.2025 13:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Warning โ€” 23 Million New Plaintext Credentials Leaked Online Researchers uncover 23 million new credentials leaked in public, including passwords, authentication tokens and more.

By me @forbes.com: 23 million new secrets leaked. When will it ever end? #kudos @gitguardian.com for the analysis.

#infosec

www.forbes.com/sites/daveyw...

12.05.2025 13:09 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
RSA Conference 2025: How Agentic AI Is Redefining Trust, Identity, and Access at Scale RSAC 2025 revealed that AI agents are reshaping trust and identity. Learn what top CISOs are doing about it and how the conversation about NHI governance is evolving.

CISOs at RSAC 2025: โ€œAI wonโ€™t wait for your approval.โ€ Agentic AI is here, with keys and autonomy. Got NHI governance yet? ๐Ÿ”‘๐Ÿšช
Read our recap of the world's largest security conference

blog.gitguardian.com/rsa-conferen...

09.05.2025 15:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
xAI Secret Leak: The Story of a Disclosure AI adoption accelerates secret sprawl as organizations connect to multiple providers. Our investigation of a leaked xAI API key, which granted access to unreleased Grok models, reveals critical flaws ...

A few months ago, our automated detection platform uncovered an xAI API key exposed on public GitHub. What stood out was the key's broad accessโ€”not just public models, but unreleased and private ones tied to projects at SpaceX and Tesla.

๐ŸšจMore details here blog.gitguardian.com/xai-secret-l...

09.05.2025 12:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

In this episode of the Security Repo Podcast, Chris Lindsey dives deep into the realities of using AI in software development and its security implications, including the concept of โ€œShadow AI.โ€

www.youtube.com/watch?v=1NBn...

08.05.2025 17:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Secrets Sprawl and AI: Why Your Non-Human Identities Need Attention Before You Deploy That LLM Your RAG implementation can expose secrets in some unexpected ways. Secure your LLM deployments and scrub knowledge bases to prevent your secrets from leaking.

Your chatbot might be the friendliest secrets-leaking intern you never hired ๐Ÿค–๐Ÿ’ฅ
NHIs + RAG = recipe for exposing root passwords in plain text.
Clean your data. Govern your bots.

Details
๐Ÿ‘‰
blog.gitguardian.com/before-you-d...

22.04.2025 14:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ATLSecCon 2025: Security Readiness Means Human Readiness LLMs wonโ€™t fix a broken SOC, but apprenticeship might. ATLSecCon 2025 revealed how outdated hiring and cultural gatekeeping are breaking cybersecurity from the inside out.

Cybersecurity isnโ€™t short on toolsโ€”itโ€™s short on trust, empathy, and apprenticeships. ATLSecCon 2025 brought ๐Ÿ”ฅ

LLMs โ‰  magic. Humans still matter.
Full recap: blog.gitguardian.com/atlseccon-20...

18.04.2025 18:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI Is the New Trust Boundary: STL TechWeek Reveals the Risk Shift At St. Louis TechWeek 2025, AI took center stage as industry thought leaders shared sessions warning about inputs, data health, and how agents are the new attack surface.

What lessons did @mdwayne-real.bsky.social learn at #STLTechWeek 2025?

Here is his blog post about the experience.

blog.gitguardian.com/stl-techweek...

09.04.2025 15:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Hidden Breach: Secrets Leaked Outside the Codebase Pose a Serious Threat Secrets aren't just in code. GitGuardianโ€™s 2025 report shows major leaks in collaboration tools like Slack, Jira, and Confluence. Hereโ€™s what security teams need to know.

Your secrets aren't just in code anymore... ๐Ÿ‘€
They're in Slack, Jira, and Confluence.

GitGuardianโ€™s 2025 report drops the mic on secrets sprawl in collab tools.

38% of those leaks? Critical.

๐Ÿ“‰ Stop pretending internal = secure:

blog.gitguardian.com/secrets-leak...

31.03.2025 14:37 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SnowFROC 2025: A Chilly Reminder That OWASP Matters and Exploring Secure Coding Practices with AI Coding Bots At Denver's SnowFROC, security pros tackled the importance of OWASPโ€™s evolving Top 10 and exposed the current shortcomings of AI-generated code for production systems.

They call it *Copilot* not *Autopilot* for a reason. ๐Ÿšซ

โœˆ๏ธ #SnowFROC2025 showed AI code gen is cool, but def not ready for prime timeโ€”especially without security guardrails.

More insights here: blog.gitguardian.com/snowfroc-2025/

27.03.2025 17:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
The State And Future Of Cybersecurity Training - Zach Hill
YouTube video by The Security Repo The State And Future Of Cybersecurity Training - Zach Hill

Tune into The State And Future Of Cybersecurity Training with Zach Hill from Antisyphon Training, the latest episode of the Security Repo Podcast

youtu.be/GTnX4SgvV4M

25.03.2025 21:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

70% of leaked secrets remain active two years later

๐Ÿ“– Read more: www.helpnetsecurity.com/2025/03/20/l...

#cybersecurity #cybersecuritynews #secretsmanagement @gitguardian.com

20.03.2025 08:06 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Addressing The Growing Challenge of Generic Secrets: Beyond GitHub's Push Protection Generic secrets are hard to detect and are getting leaked more often. See how GitGuardian offers advanced protection where GitHub's push protection falls short.

Generic secrets are the most common leaks of 2025.

๐Ÿ”“ GitHub's push protection catches some, but GitGuardian's ML-powered detection tackles the toughest onesโ€”before they hit your repo.

Ready for next-level protection?
๐Ÿ‘‰ c.gitguardian.com/gsghp

17.03.2025 16:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Devnexus: Bringing Java Into The Age Of AI The largest Java community conference, Devnexus 2025, tackled AI, security, and Javaโ€™s role in enterprise development. Read key takeaways for securing applications.

Java turns 30, but itโ€™s not slowing down!

๐Ÿš€ At #Devnexus2025, AI, security, and secrets management took center stage. From tackling AI risks to securing Java apps, the future is boldโ€”and safe! ๐Ÿ”’ #Java #AppSec

blog.gitguardian.com/devnexus-2025

14.03.2025 13:44 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
State of Secrets Sprawl Report 2025 The 2025 State of Secrets Sprawl report measures the exposure of and remediation of leaked secrets within GitHub and how it is evolving year to year.

New publication from @gitguardian.com on the problem of secrets sprawl in GitHub. Non-human identities ( #NHI) like secrets are a festering part of the enterprise #cybersecurity attack surface - www.gitguardian.com/state-of-sec... .

11.03.2025 18:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail
07.03.2025 17:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitGuardian Integration with HashiCorp Vault Centralize secrets management and reduce blind spots!

๐Ÿš€ Vault sprawl and NHI secrets got you stressed? GitGuardianโ€™s new HashiCorp Vault integration brings visibility, control, and automated remediation to your secrets management! ๐Ÿ”
Say goodbye to blind spots. Learn more ๐Ÿ‘‰
blog.gitguardian.com/hashicorp-va...

03.03.2025 14:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Threat Intelligence and AI Research In Austin: IntelliC0N 2025 At IntelliC0N 2025, threat intelligence leaders shared strategies for using AI, uncovering blind spots, improving communication, and improving cyber defenses overall.

What can AI do for Threat intelligence?

This was the question at the heart of the discussion at #IntelliC0N 2025.

Learn more in our recap: blog.gitguardian.com/intellic0n-2...

25.02.2025 15:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Wild West Hackin' Fest @ Mile High 2025: Building a Stronger Security Community Together The Denver edition of WWHF showcased security insights, from red teaming to DevSecOps. Learn key lessons on collaboration, Git security, and AWS policies

๐Ÿšจ Leaked AWS keys arenโ€™t fully revoked! At #WWHF #MileHigh2025, we learned that AWSโ€™s CompromisedKeyQuarantine policy doesnโ€™t prevent all actionsโ€”itโ€™s not really a security feature.

Rotate any and all exposed secrets immediately!

More insights:
c.gitguardian.com/wwhfmh

13.02.2025 16:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Non-Human Identity Security in the Age of AI The rise of AI in enterprises has expanded the attack surface. Learn how GitGuardian can help you secure non-human identities and prevent unauthorized access.

๐Ÿค– AI-powered agents are revolutionizing workflowsโ€”but theyโ€™re also expanding the attack surface! Non-human identities (NHIs) need strong security controls to prevent unauthorized access.

๐Ÿ”‘ Secure API keys
๐Ÿ“œ Prevent secrets sprawl
๐Ÿ›ก๏ธ Enforce least privilege

Learn more:
c.gitguardian.com/ai-nhi

12.02.2025 14:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Critical Role of CISOs in Managing IAM - Including Non-Human Identities NHIs outnumber human users in enterprises, yet many IAM strategies ignore them. Learn why CISOs must own NHI governance to prevent security breaches.

IAM without non-human identity (NHI) governance? Incomplete. โŒ

Service accounts, APIs, & machine identities are prime targets for attackers. Itโ€™s time for CISOs to take charge & secure NHIs. ๐Ÿ”

Full breakdown:

c.gitguardian.com/ciso-iam

11.02.2025 14:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@gitguardian.com is following 20 prominent accounts