
AI Agents Rerun the Service-Account Mistake: The Governance Gap Nobody Sized
Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.


Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.


The Korean GitHub token leaks and CISA's public-repo exposure were both filed as secrets leaks. What got out was not a file but a live identity. This piece argues that security leaders should treat API keys as identities and shift the defense from prevention rate to how fast you detect what has already leaked.


Secret scanning alert: Resolved. Credential status: Active. Deleting a secret from code is not the same as revoking it. Inside the Zombie Key kill chain.


Aqua Security's Trivy was compromised by TeamPCP, cascading into LiteLLM. A 7-phase Cyber Kill Chain and MITRE ATT&CK analysis of how incomplete credential rotation turned a single breach into a five-ecosystem catastrophe.


Attackers exploited a GitHub Actions vulnerability to compromise the Nx package. Analysis of the attack chain, who was affected, and how to detect similar threats.


We found live API keys in 0.45% of public Vercel deployments. AWS credentials, Stripe secrets, GitHub tokens. Here is what exposes them (NEXT_PUBLIC_ misuse is only one), how attackers chain a single key into full cloud compromise, and what to change in your setup this week.


Vigilant Ally is Cremit’s initiative to help developers find and close the secrets they have exposed on GitHub.

We use cookies to measure traffic and ad performance. Declining costs you nothing: the site keeps working, and all that stays is your language and this answer. Everything we load is listed in the cookie policy