logo

Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security

ID: 6d98554e-edac-5ea1-875a-05b57beeaac1

STIX ID: report--6d98554e-edac-5ea1-875a-05b57beeaac1

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2021-12-01

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

This transcript discusses the growing risk of "secret sprawl": developer credentials, API keys, certificates and other secrets accidentally committed to public and private source code repositories (notably GitHub). It explains how attackers rapidly harvest such secrets (sometimes within minutes), cites breaches enabled by leaked credentials, and outlines mitigation strategies including automated secret detection, pre-commit checks, repository history scanning, rotation of exposed keys, and centralized secret management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.