Syndicated Blog

GitGuardian Blog – Take Control of Your Secrets Security
A blog for developers, security engineers, and other cybersecurity professionals to learn about secrets and code security, DevSecOps, Infra-as-Code and much more.
How GitGuardian and Akeyless Secure Machine Identities Across Environments

How GitGuardian and Akeyless Secure Machine Identities Across Environments

| | non-human identity
See how GitGuardian's deep discovery, combined with Akeyless's automation, delivers full secrets lifecycle control ...
Why Most Exposed Secrets Never Get Fixed

Why Most Exposed Secrets Never Get Fixed

Our latest State of Secrets Sprawl 2025 research reveals a troubling reality: the majority of leaked corporate secrets found in public code repositories continue to provide access to systems for years after ...
Security Isn’t A Solo Sport: Community, Burnout, and Identity at BSides312

Security Isn’t A Solo Sport: Community, Burnout, and Identity at BSides312

| | Conferences
At BSides312 in Chicago, experts showed that defending systems requires defending people, with trust, inclusion, and communication as key controls. Defense is deeply human ...
Security Starts With Developer Enablement: Lessons From PHP TEK 2025

Security Starts With Developer Enablement: Lessons From PHP TEK 2025

| | Conferences
PHP TEK 2025 revealed how empowering developers through clear, embedded security practices strengthens defenses without adding operational friction ...
Building a Secure LLM Gateway (and an MCP Server) with GitGuardian & AWS Lambda

Building a Secure LLM Gateway (and an MCP Server) with GitGuardian & AWS Lambda

How I wrapped large-language-model power in a safety blanket of secrets-detection, chunking, and serverless scale ...
Navigating the New Frontiers of Identity: Insights from KuppingerCole EIC Summit 2025

Navigating the New Frontiers of Identity: Insights from KuppingerCole EIC Summit 2025

| | Conferences
Discover why machine identities are the new security frontier from KuppingerCole EIC 2025. Learn about secrets sprawl, AI agents, and why traditional IAM fails to protect NHIs in this GitGuardian recap ...
Standards for a Machine‑First Future: SPICE, WIMSE, and SCITT

Standards for a Machine‑First Future: SPICE, WIMSE, and SCITT

Discover how SPICE, WIMSE, and SCITT are redefining workload identity, digital trust, and software supply chain integrity in modern machine-first environments ...
Securing Critical Infrastructure: GitGuardian Partners with ONE-ISAC to Protect Oil & Natural Energy Operations

Securing Critical Infrastructure: GitGuardian Partners with ONE-ISAC to Protect Oil & Natural Energy Operations

| | GitGuardian
This collaboration brings GitGuardian's expertise in secrets detection and non-human identity protection to the oil and natural energy sector, addressing unique challenges in operational technology environments ...
Fresh From The Docks: Uncovering 100,000 Valid Secrets in DockerHub

Fresh From The Docks: Uncovering 100,000 Valid Secrets in DockerHub

This post details the methodology used to scan 15 million Docker images, uncovering a staggering 100,000 valid secrets, including AWS, GCP, and GitHub tokens belonging to Fortune 500 companies. This emphasizes the ...
Why Your Biggest Secret Leaks Happen Behind the Firewall: Private vs. Public Repos

Why Your Biggest Secret Leaks Happen Behind the Firewall: Private vs. Public Repos

Private repos leak plaintext secrets 8x more often than public ones. Learn why internal codebases are the biggest blind spot in your secrets management strategy ...