Please turn JavaScript on
GitGuardian Blog - Take Control of Your Secrets Security icon

GitGuardian Blog - Take Control of Your Secrets Security

Following GitGuardian Blog - Take Control of Your Secrets Security's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with GitGuardian Blog - Take Control of Your Secrets Security!

GitGuardian Blog - Take Control of Your Secrets Security: GitGuardian Blog - NHI Governance & Secrets Security

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.43 / day

Message History

The March compromise of litellm lasted about 40 minutes on PyPI. This week we learned what the attackers stole in that time.

On August 12, 2026,


Read full story

The springs at Las Vegas were essential to western travel. The Old Spanish Trail connected Santa Fe to Southern California through more than a thousand miles of difficult desert terrain. Travelers and their animals depended on those ...


Read full story
Key findingsIt's a secrets problem before it's an identity problem. Many AI agents don't have their own distinct identity, so they operate using API keys, tokens, and other credentials issued to humans or workloads.Those credentials can sit outside agent-specific identity controls. When no enterprise IdP mediates the exchange, agent activity can...

Read full story

Most large enterprises have some version of a vault program, the combination of policy, platform, process, and ownership used to manage machine credentials. It includes the secrets manager itself, the teams that operate it, the IAM policies that govern it, and the application teams expected to use it. The credentials themselves belong to machine identities: the service accoun...


Read full story

We have stopped counting the number of waves in the Shai-Hulud attack series, but this week has seen the rise of yet another iteration.

This campaign started with the infection of the [email protected] npm package at 9:35 a.m. UTC on Aug. 4, 2026, and quickly spread across the ecosystem. The compromise chain reportedly affected more than 800 packages across thousands of...


Read full story