Moltbot Personal Assistant Goes Viral—And So Do Your Secrets

Moltbot Personal Assistant Goes Viral—And So Do Your Secrets

Early 2026, Moltbot a new AI personal assistant went viral. GitGuardian detected 200+ leaked secrets related to it, including from healthcare and fintech companies. Our contribution to Moltbot: a skill that turns secret scanning into a conversational prompt, letting users ask "is this safe?" ... Read More
Shai-Hulud 2.0: over 14,000 secrets exposed

Shai-Hulud 2.0: over 14,000 secrets exposed

| | Security Research
On November 24, a new wave of the Shai-Hulud supply chain attack emerged. The threat actors exfiltrate stolen credentials directly to GitHub repositories created with compromised tokens. GitGuardian identified 14,206 secrets across 487 organizations, with 2,485 still valid ... Read More
How Cybercriminal Organizations Weaponize Exposed Secrets

How Cybercriminal Organizations Weaponize Exposed Secrets

| | Security Research
The threat GitGuardian has long-anticipated is now a reality: criminal groups are executing systematic attacks targeting hardcoded credentials and over-permissive IAM configurations. The situation escalated when Shiny Hunters and Crimson Collective formed an alliance to coordinate efforts ... Read More
Red Hat GitLab Breach: The Crimson Collective's Attack

Red Hat GitLab Breach: The Crimson Collective’s Attack

| | Breach explained
A comprehensive analysis of the breach that exposed 570GB of consulting data and put 800 organizations at risk ... Read More
When Google Says "Scan for Secrets": A Complete Guide to Finding Hidden Credentials in Salesforce

When Google Says “Scan for Secrets”: A Complete Guide to Finding Hidden Credentials in Salesforce

| | Breach explained
The Salesloft Drift breach affected hundreds of organizations through Salesforce, including Cloudflare, Palo Alto Networks, and Zscaler. Google now explicitly recommends running secrets scanning tools across Salesforce data—here's your complete guide ... Read More
The Nx "s1ngularity" Attack: Inside the Credential Leak

The Nx “s1ngularity” Attack: Inside the Credential Leak

| | Breach explained
On August 26, 2025, Nx, the popular build platform with millions of weekly downloads, was compromised with credential-harvesting malware. Using GitGuardian's monitoring data, we analyzed the exfiltrated credentials and reconstructed a fuller scope of exposure ... Read More
GreHack 2024

Exploiting Public APP_KEY Leaks to Achieve RCE in Hundreds of Laravel Applications

Laravel APP_KEY leaks enable RCE via deserialization attacks. Collaboration with Synacktiv scaled findings to 600 vulnerable applications using 260K exposed keys from GitHub. Analysis reveals 35% of exposures coincide with other critical secrets including database, cloud tokens, and API credentials ... Read More
Fresh From The Docks: Uncovering 100,000 Valid Secrets in DockerHub

Fresh From The Docks: Uncovering 100,000 Valid Secrets in DockerHub

This post details the methodology used to scan 15 million Docker images, uncovering a staggering 100,000 valid secrets, including AWS, GCP, and GitHub tokens belonging to Fortune 500 companies. This emphasizes the critical need for improved security practices in containerized environments ... Read More
Security First, Transparency Always: Inside GitGuardian’s Responsible Disclosure Process

Security First, Transparency Always: Inside GitGuardian’s Responsible Disclosure Process

| | Security Research
In the past 6 months, our security research team disclosed 24 critical vulnerabilities. Most have been successfully remediated. Our team's contributions to cybersecurity have been formally recognized, with our researchers being listed in both Bayer's and Oracle's Security Researcher Hall of Fame ... Read More
What Happened in the U.S. Department of the Treasury Breach? A Detailed Summary

What Happened in the U.S. Department of the Treasury Breach? A Detailed Summary

| | Breach explained
The U.S. Department of the Treasury suffered a major security incident when a Chinese threat actor compromised its third-party cybersecurity service BeyondTrust. The attackers obtained an API key that allowed them to bypass security measures and access unclassified documents ... Read More