Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Back to Blog
Tag

Secret Detection

15 posts
NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)
Apr 30, 2026

NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)

Eight types of dangerous NHI credentials. One framework to find, classify, and eliminate them all. The complete NHI Kill Chain series summary with Cyber Kill Chain and MITRE ATT&CK mapping.

Ben Kim
Ben Kim
Founder & CEO
AITU CTF Final 2026 Writeup
Apr 29, 2026

AITU CTF Final 2026 Writeup

Full writeup of the AITU CTF Final (April 25-26, 2026), a HackCity-format competition. We walk through exploiting DMZ hosts via XXE, SSTI, and SQLi, pivoting into the DEV segment through AD lateral movement, escaping a privileged Docker container via cgroup abuse, and breaching a healthcare system through JWT JKU header injection.

Ethan Kim
Ethan Kim
CTO
Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)
Apr 17, 2026

Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)

A PostgreSQL master password drifted across seven platform types — from Secrets Manager to GitHub, Jenkins, Docker Hub, Jira, Confluence, and Slack. Each security tool saw its own silo. None saw the full picture.

Ben Kim
Ben Kim
Founder & CEO
The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure
Apr 15, 2026

The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure

An organization's core credentials sat in public repositories for years. The security industry's answer: "Out of scope."

Ben Kim
Ben Kim
Founder & CEO
Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)
Apr 11, 2026

Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)

A single Stripe API key was copied to 14 locations over three years. When a QA repo went public, the key was exposed — and revoking it meant breaking 14 services simultaneously.

Ben Kim
Ben Kim
Founder & CEO
Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)
Apr 10, 2026

Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)

A single AWS key, never rotated for 3 years, spread across 7 systems. When a supply chain attack hit a Terraform CI plugin, the key gave attackers full infrastructure access. Inside the Aged Key kill chain and how to defend against long-lived credentials.

Ben Kim
Ben Kim
Founder & CEO
Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)
Apr 5, 2026

Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)

A single production outage left credentials in six non-code platforms — Slack, Jira, Confluence, Sentry, Datadog, and PagerDuty. Your secret scanner found none of them. Inside the Shadow Key kill chain.

Ben Kim
Ben Kim
Founder & CEO
Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)
Mar 17, 2026

Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)

A .env file pushed to a public GitHub repo is found by attacker bots in 4 minutes. We map the full kill chain — from credential exposure to infrastructure compromise and show how to detect and respond before the damage is done.

Ben Kim
Ben Kim
Founder & CEO
Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security
Apr 23, 2025

Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security

Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security

Ben Kim
Ben Kim
Founder & CEO
CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy
Apr 18, 2025

CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy

Where credentials leak in modern CI/CD pipelines, what to scan at each stage (pre-commit, build, deploy), and how to integrate secret detection without slowing delivery.

Ben Kim
Ben Kim
Founder & CEO
Stop Secrets Sprawl: Shifting Left for Effective Secret Detection
Apr 14, 2025

Stop Secrets Sprawl: Shifting Left for Effective Secret Detection

Stop Secrets Sprawl: Shifting Left for Effective Secret Detection

Ben Kim
Ben Kim
Founder & CEO
Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical
Apr 14, 2025

Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical

Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical

Ben Kim
Ben Kim
Founder & CEO
Rising Data Breach Costs: Secret Detection's Role
Apr 4, 2025

Rising Data Breach Costs: Secret Detection's Role

Rising Data Breach Costs: Secret Detection's Role

Ben Kim
Ben Kim
Founder & CEO
Frontend API Key Leaks: Finding Exposed Secrets in JavaScript Bundles (NEXT_PUBLIC_, .env.local)
Nov 17, 2024

Frontend API Key Leaks: Finding Exposed Secrets in JavaScript Bundles (NEXT_PUBLIC_, .env.local)

JavaScript bundles and source maps routinely leak API keys that never should have reached the browser. Here is how the leak happens, how to find it, and how to stop it.

Ben Kim
Ben Kim
Founder & CEO
What Is Secret Detection? A Beginner’s Guide
Feb 26, 2024

What Is Secret Detection? A Beginner’s Guide

What Is Secret Detection? A Beginner’s Guide

Ben Kim
Ben Kim
Founder & CEO