logo

AI frenzy feeds credential chaos, secrets spread through code, tools, and infrastructure

ID: 7d239e9c-11c5-58a6-82d1-d62f49c45d6a

STIX ID: report--7d239e9c-11c5-58a6-82d1-d62f49c45d6a

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: Anamarija Pogorelec

...
...

GitGuardian's "State of Secrets Sprawl" report documents a substantial and growing exposure of hardcoded credentials — citing 28.65 million new secrets in public GitHub commits in 2025 — and shows that leaked credentials now span public and internal repositories, collaboration tools (Slack, Jira, Confluence), self-hosted infrastructure (GitLab, Docker registries), and AI development workflows. The report warns that many exposed secrets remain valid for years, remediation is slow due to dependencies and prioritization gaps, and the proliferation of AI services and automation is increasing the volume and distribution of secrets, amplifying operational risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.