Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Back to Blog
Tag

Secret Detection

19 posts
Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.
Aug 5, 2026

Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.

Every secret scanner hands you a big number, and almost nobody can act on it. When we verified each finding against the service that issued it, a five-figure detection count became a three-figure inventory of credentials that actually work. This is what that collapse means for how you prioritize, what you suppress, and what you tell your board.

Ben Kim
Ben Kim
Founder & CEO
From Research to Product: How Cremit Built Argus to Solve the NHI Security Gap
Jul 28, 2026

From Research to Product: How Cremit Built Argus to Solve the NHI Security Gap

We spent six months documenting why non-human identity (NHI) security fails in real organizations, from bug bounties that call leaked keys "out of scope" to the nine-part NHI Kill Chain. Argus is the product we built from what that research proved.

Ben Kim
Ben Kim
Founder & CEO
Secret Scanning False Positives: Why They Happen and How to Eliminate Them
Jul 22, 2026

Secret Scanning False Positives: Why They Happen and How to Eliminate Them

Secret scanners are notorious for burying teams in false alarms, and every ignored alert is a place a real breach can hide. This technical guide breaks down the two root causes of secret scanning false positives, why importing open-source rulesets makes them worse, and how active validation turns noisy findings into a signal your team can actually trust.

Ben Kim
Ben Kim
Founder & CEO
The Identity You Can't See Is the One That Breaks You
Jul 15, 2026

The Identity You Can't See Is the One That Breaks You

The Korean GitHub token leaks and CISA's public-repo exposure were both filed as secrets leaks. What got out was not a file but a live identity. This piece argues that security leaders should treat API keys as identities and shift the defense from prevention rate to how fast you detect what has already leaked.

Ben Kim
Ben Kim
Founder & CEO
NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)
Apr 30, 2026

NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)

Eight types of dangerous NHI credentials. One framework to find, classify, and eliminate them all. The complete NHI Kill Chain series summary with Cyber Kill Chain and MITRE ATT&CK mapping.

Ben Kim
Ben Kim
Founder & CEO
AITU CTF Final 2026 Writeup
Apr 29, 2026

AITU CTF Final 2026 Writeup

Full writeup of the AITU CTF Final (April 25-26, 2026), a HackCity-format competition. We walk through exploiting DMZ hosts via XXE, SSTI, and SQLi, pivoting into the DEV segment through AD lateral movement, escaping a privileged Docker container via cgroup abuse, and breaching a healthcare system through JWT JKU header injection.

Ethan Kim
Ethan Kim
CTO
Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)
Apr 17, 2026

Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)

A PostgreSQL master password drifted across seven platform types, from Secrets Manager to GitHub, Jenkins, Docker Hub, Jira, Confluence and Slack. Each security tool saw its own silo. None saw the full picture.

Ben Kim
Ben Kim
Founder & CEO
The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure
Apr 15, 2026

The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure

An organization's core credentials sat in public repositories for years. The security industry's answer: "Out of scope."

Ben Kim
Ben Kim
Founder & CEO
Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)
Apr 11, 2026

Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)

A single Stripe API key was copied to 14 locations over three years. When a QA repo went public, the key was exposed, and revoking it meant breaking 14 services at once.

Ben Kim
Ben Kim
Founder & CEO
Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)
Apr 10, 2026

Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)

A single AWS key, never rotated for 3 years, spread across 7 systems. When a supply chain attack hit a Terraform CI plugin, the key gave attackers full infrastructure access. Inside the Aged Key kill chain and how to defend against long-lived credentials.

Ben Kim
Ben Kim
Founder & CEO
Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)
Apr 5, 2026

Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)

A single production outage left credentials in six non-code platforms: Slack, Jira, Confluence, Sentry, Datadog and PagerDuty. Your secret scanner found none of them. Inside the Shadow Key kill chain.

Ben Kim
Ben Kim
Founder & CEO
Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)
Mar 17, 2026

Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)

A .env file pushed to a public GitHub repo is found by attacker bots in 4 minutes. We map the full kill chain, from credential exposure to infrastructure compromise, and show how to detect and respond before the damage is done.

Ben Kim
Ben Kim
Founder & CEO
Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security
Apr 23, 2025

Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security

Lifecycle management and scheduled rotation leave a window open. What continuous detection covers inside it.

Ben Kim
Ben Kim
Founder & CEO
CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy
Apr 18, 2025

CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy

Where credentials leak in modern CI/CD pipelines, what to scan at each stage (pre-commit, build, deploy), and how to integrate secret detection without slowing delivery.

Ben Kim
Ben Kim
Founder & CEO
Stop Secrets Sprawl: Shifting Left for Effective Secret Detection
Apr 14, 2025

Stop Secrets Sprawl: Shifting Left for Effective Secret Detection

Moving secret detection left without slowing delivery. What it costs to catch a key before the commit versus after the deploy.

Ben Kim
Ben Kim
Founder & CEO
Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical
Apr 14, 2025

Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical

Credentials ride into S3 buckets alongside backups and config files. How they get there, and why they surface late.

Ben Kim
Ben Kim
Founder & CEO
Rising Data Breach Costs: Secret Detection's Role
Apr 4, 2025

Rising Data Breach Costs: Secret Detection's Role

Breach costs keep climbing. Which part of that number secret detection actually reduces.

Ben Kim
Ben Kim
Founder & CEO
Frontend API Key Leaks: Finding Exposed Secrets in JavaScript Bundles (NEXT_PUBLIC_, .env.local)
Nov 17, 2024

Frontend API Key Leaks: Finding Exposed Secrets in JavaScript Bundles (NEXT_PUBLIC_, .env.local)

JavaScript bundles and source maps routinely leak API keys that never should have reached the browser. Here is how the leak happens, how to find it, and how to stop it.

Ben Kim
Ben Kim
Founder & CEO
What Is Secret Detection? A Beginner’s Guide
Feb 26, 2024

What Is Secret Detection? A Beginner’s Guide

What secret detection is, how it works, and what it looks at across code, containers and cloud workloads.

Ben Kim
Ben Kim
Founder & CEO
Secret Detection | Cremit Blog | Cremit