Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Back to Blog
Category

Technical Guides

Best practices and technical tutorials

11 posts
Secret Scanning False Positives: Why They Happen and How to Eliminate Them
Jul 22, 2026

Secret Scanning False Positives: Why They Happen and How to Eliminate Them

Secret scanners are notorious for burying teams in false alarms, and every ignored alert is a place a real breach can hide. This technical guide breaks down the two root causes of secret scanning false positives, why importing open-source rulesets makes them worse, and how active validation turns noisy findings into a signal your team can actually trust.

Ben Kim
Ben Kim
Founder & CEO
Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel
Jun 13, 2026

Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel

A leaked Slack incoming webhook is usually triaged as low severity: write-only, one channel, no data access. The moment an AI agent reads that channel and can act with tools, that write-only primitive becomes an indirect prompt injection path into the agent's privileges. Here is the full kill chain, the exact preconditions, and how to defend it.

Ben Kim
Ben Kim
Founder & CEO
Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security
Apr 23, 2025

Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security

Lifecycle management and scheduled rotation leave a window open. What continuous detection covers inside it.

Ben Kim
Ben Kim
Founder & CEO
CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy
Apr 18, 2025

CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy

Where credentials leak in modern CI/CD pipelines, what to scan at each stage (pre-commit, build, deploy), and how to integrate secret detection without slowing delivery.

Ben Kim
Ben Kim
Founder & CEO
Stop Secrets Sprawl: Shifting Left for Effective Secret Detection
Apr 14, 2025

Stop Secrets Sprawl: Shifting Left for Effective Secret Detection

Moving secret detection left without slowing delivery. What it costs to catch a key before the commit versus after the deploy.

Ben Kim
Ben Kim
Founder & CEO
Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical
Apr 14, 2025

Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical

Credentials ride into S3 buckets alongside backups and config files. How they get there, and why they surface late.

Ben Kim
Ben Kim
Founder & CEO
Rising Data Breach Costs: Secret Detection's Role
Apr 4, 2025

Rising Data Breach Costs: Secret Detection's Role

Breach costs keep climbing. Which part of that number secret detection actually reduces.

Ben Kim
Ben Kim
Founder & CEO
Stop the Sprawl: Introducing Cremit’s AWS S3 Non-Human Identity Detection
Feb 25, 2025

Stop the Sprawl: Introducing Cremit’s AWS S3 Non-Human Identity Detection

S3 buckets accumulate the machine roles, automated services and API keys that read and write to them. Cremit now scans those buckets continuously with read-only access and returns the inventory.

Ben Kim
Ben Kim
Founder & CEO
Build vs. Buy: Making the Right Choice for Secrets Detection
Feb 25, 2025

Build vs. Buy: Making the Right Choice for Secrets Detection

Building secret detection or buying it. The factors that actually decide it, one at a time.

Ben Kim
Ben Kim
Founder & CEO
Introducing Probe! Cremit's New Detection Engine
Aug 3, 2024

Introducing Probe! Cremit's New Detection Engine

Regex-based scanners miss credential formats nobody told them about. What Probe, Cremit’s detection engine, does differently.

Ben Kim
Ben Kim
Founder & CEO
What Is Secret Detection? A Beginner’s Guide
Feb 26, 2024

What Is Secret Detection? A Beginner’s Guide

What secret detection is, how it works, and what it looks at across code, containers and cloud workloads.

Ben Kim
Ben Kim
Founder & CEO
Technical Guides | Cremit Blog | Cremit