Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Back to Blog
Tag

Secret Scanning

8 posts
Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.
Aug 5, 2026

Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.

Every secret scanner hands you a big number, and almost nobody can act on it. When we verified each finding against the service that issued it, a five-figure detection count became a three-figure inventory of credentials that actually work. This is what that collapse means for how you prioritize, what you suppress, and what you tell your board.

Ben Kim
Ben Kim
Founder & CEO
Secret Scanning False Positives: Why They Happen and How to Eliminate Them
Jul 22, 2026

Secret Scanning False Positives: Why They Happen and How to Eliminate Them

Secret scanners are notorious for burying teams in false alarms, and every ignored alert is a place a real breach can hide. This technical guide breaks down the two root causes of secret scanning false positives, why importing open-source rulesets makes them worse, and how active validation turns noisy findings into a signal your team can actually trust.

Ben Kim
Ben Kim
Founder & CEO
Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel
Jun 13, 2026

Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel

A leaked Slack incoming webhook is usually triaged as low severity: write-only, one channel, no data access. The moment an AI agent reads that channel and can act with tools, that write-only primitive becomes an indirect prompt injection path into the agent's privileges. Here is the full kill chain, the exact preconditions, and how to defend it.

Ben Kim
Ben Kim
Founder & CEO
Bitwarden CLI Hack (April 2026): How a 90-Minute npm Window Stole AWS, GCP, GitHub Tokens
Apr 25, 2026

Bitwarden CLI Hack (April 2026): How a 90-Minute npm Window Stole AWS, GCP, GitHub Tokens

On April 22, 2026, the official @bitwarden/cli@2026.4.0 npm package was malicious for ~90 minutes. A self-propagating worm exfiltrated AWS, Azure, GCP, GitHub, npm, SSH, and AI tooling credentials from CI runners. Vaults stayed safe. CI tokens did not. Timeline, NHI kill-chain mapping, and a 10-minute checklist to know whether you were affected.

Ben Kim
Ben Kim
Founder & CEO
Vercel's April 2026 Incident Is a Textbook NHI Problem: What to Rotate and Why
Apr 20, 2026

Vercel's April 2026 Incident Is a Textbook NHI Problem: What to Rotate and Why

Vercel confirmed an unauthorized-access incident on April 19, 2026 that started in a third-party AI tool, pivoted through Google Workspace, and reached environment variables in a subset of customer projects. The exposure surface is every env var that was not marked sensitive. Here is what is confirmed, what is noise, and what to rotate first.

Ben Kim
Ben Kim
Founder & CEO
Expired Credentials That Still Work: The Zombie Key Problem (NHI Kill Chain #5)
Apr 14, 2026

Expired Credentials That Still Work: The Zombie Key Problem (NHI Kill Chain #5)

Secret scanning alert: Resolved. Credential status: Active. Deleting a secret from code is not the same as revoking it. Inside the Zombie Key kill chain.

Ben Kim
Ben Kim
Founder & CEO
Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)
Mar 17, 2026

Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)

A .env file pushed to a public GitHub repo is found by attacker bots in 4 minutes. We map the full kill chain, from credential exposure to infrastructure compromise, and show how to detect and respond before the damage is done.

Ben Kim
Ben Kim
Founder & CEO
Git Secret Scanning: Complete Guide for 2026
Jan 26, 2026

Git Secret Scanning: Complete Guide for 2026

Complete guide to git secret scanning tools. Compare TruffleHog, GitGuardian, GitHub Advanced Security, and Cremit. Learn implementation strategies with real CI/CD examples

Ben Kim
Ben Kim
Founder & CEO
Secret Scanning | Cremit Blog | Cremit