logo

The state of secrets security: 7 action items for better managing risk

ID: 4033c2aa-0239-523f-9024-e1909993c329

STIX ID: report--4033c2aa-0239-523f-9024-e1909993c329

Feed Name: ReversingLabs Blog

Date Published: 2024-04-10

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

This report outlines GitGuardian’s 2024 findings on the escalating exposure of development secrets on GitHub, noting a 28% year-over-year rise and that 90% of exposed secrets remain active for at least five days post-notification. Key takeaways include the outsized risk of .env files, the insufficiency of automated detection and AI tools alone, the need to guide developers beyond alerts, the limits and risks of DMCA takedowns, and the imperative to revoke secrets immediately to avoid “zombie leaks.” It advocates a holistic, multilayered strategy—real-time monitoring, shift-left practices, and centralized secrets management—to reduce software supply chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.