<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-unattributed-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/3bb901ab01dc849479417d1eb5db42d77dde15d8-1672x941.webp</image:loc>
      <image:title>When an exposed credential has no clear owner</image:title>
      <image:caption>How to verify, investigate, assign, and replace an exposed credential when the service owner is unclear.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-series-summary</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/cebc7b2fd7f537fe3793f1aa2b3ed96bd911d254-1672x941.webp</image:loc>
      <image:title>Eight credential exposure patterns and how to respond</image:title>
      <image:caption>A practical summary of eight NHI credential exposure patterns, the evidence to check, and what Cremit Platform can help investigate.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/behind-the-code-best-practices-for-identifying-hidden-secrets</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/c8eae41ee238c30de459a167cb795bb987e43e52-1672x941.webp</image:loc>
      <image:title>How to find hidden credentials in code and shared tools</image:title>
      <image:caption>A practical workflow for preventing, finding, verifying, and replacing exposed credentials across code and shared tools.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/2025-cybersecurity-landscape-report</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/30563766230a7a2d8620d23d1c1de59a094c60af-1672x941.webp</image:loc>
      <image:title>2025 DBIR: what credential abuse and third-party breaches mean for teams</image:title>
      <image:caption>A sourced reading of the 2025 Verizon DBIR, with practical steps for credential inventory, leak prevention, and response.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/understanding-the-owasp-non-human-identities-nhi-top-10-threats</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/3d7e3b06a8607235fe5996d9e5bbd0faf363e1e1-2400x1260.png</image:loc>
      <image:title>OWASP NHI Top 10: what to check for each machine identity risk</image:title>
      <image:caption>The ten OWASP NHI risks explained through specific checks for service accounts, tokens, deployment systems, and owners.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/live-credentials-33-surfaces</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/live-credentials-discover.webp</image:loc>
      <image:title>Unlisted, Not Private</image:title>
      <image:caption>A full sweep of 33 public attack surfaces turned up 23,912 machine credentials that still work. We graded each by the privilege it carries, and 1,277 of them survive revocation of </image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/verified-live-credential-count</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/6ad293aeb4fef202b58f65c8bf625409b64eb9de-2400x1260.png</image:loc>
      <image:title>Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.</image:title>
      <image:caption>Every secret scanner hands you a big number, and almost nobody can act on it. When we checked the findings we could verify against the service that issued them, a five-figure detec</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/from-research-to-product-how-cremit-built-argus</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/d09ade5380cfdaa0ad59a3f4b0a979224572b2ed-2400x1260.png</image:loc>
      <image:title>From exposed credentials to Cremit Platform: the workflow we support</image:title>
      <image:caption>How Cremit Platform finds exposed credentials, verifies supported types, and routes findings to an owner, with clear limits.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/secret-scanning-false-positives-causes-and-fixes</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/secret-scanning-triage.webp</image:loc>
      <image:title>Secret scanning false positives: how to triage findings</image:title>
      <image:caption>A pattern match, a revoked key, and an unverified key need different responses. Learn how to separate them and prioritize exposed credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/ai-agents-creating-nhis-at-scale</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/441e961915a195eee0566a6a37fb309b7167f548-2400x1260.png</image:loc>
      <image:title>AI Agents Rerun the Service-Account Mistake: The Governance Gap Nobody Sized</image:title>
      <image:caption>Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/the-identity-you-cant-see</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/e9c41a3418399ea814000a70c291a5b8614bb17d-2400x1260.png</image:loc>
      <image:title>The Identity You Can&apos;t See Is the One That Breaks You</image:title>
      <image:caption>The Korean GitHub token leaks and CISA&apos;s public-repo exposure were both filed as secrets leaks. What got out was not a file but a live identity. This piece argues that security lea</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/leaked-slack-webhook-ai-agent</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/fd6a0d4e9b7af5cbe26c7071ec12a926e45a5e59-2400x1260.png</image:loc>
      <image:title>Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel</image:title>
      <image:caption>A leaked Slack incoming webhook is usually triaged as low severity: write-only, one channel, no data access. The moment an AI agent reads that channel and can act with tools, that </image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/antv-mini-shai-hulud-2026</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/9f27067685326b0e01eb5d82f9da5ce59ca0dc7c-1200x630.png</image:loc>
      <image:title>AntV npm Compromise: How Cremit Platform Pipeline Surfaced 324 Mini Shai-Hulud Catches Within 30 Minutes</image:title>
      <image:caption>Between 01:39 and 02:56 UTC on May 19, 2026, two tight publish bursts placed 639 malicious versions across 323 packages on npm. The single stolen `atool` session was only the entry</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/aitu-ctf-final-2026-writeup</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/f06daaa965889ec5e8be1361f33afca76fefd90f-4032x3024.jpg</image:loc>
      <image:title>AITU CTF Final 2026 Writeup</image:title>
      <image:caption>Full writeup of the AITU CTF Final (April 25-26, 2026), a HackCity-format competition. We walk through exploiting DMZ hosts via XXE, SSTI, and SQLi, pivoting into the DEV segment t</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/bitwarden-cli-supply-chain-attack-april-2026</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/bitwarden-cli-supply-chain.webp</image:loc>
      <image:title>Bitwarden CLI npm compromise: affected systems and response</image:title>
      <image:caption>A malicious CLI package was available on npm for 93 minutes on April 22, 2026. Check who installed it, what researchers found, and Bitwarden’s response steps.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/vercel-april-2026-incident-nhi-secret-sprawl</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/14785e509c57d22dbc58558412282e39132b972e-1200x630.png</image:loc>
      <image:title>Vercel&apos;s April 2026 Incident Is a Textbook NHI Problem: What to Rotate and Why</image:title>
      <image:caption>Vercel confirmed an unauthorized-access incident on April 19, 2026 that started in a third-party AI tool, pivoted through Google Workspace, and reached environment variables in a s</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-drifted-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/86727028270f9c22fb4bf81c72d4500eabb83045-2400x1260.png</image:loc>
      <image:title>Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)</image:title>
      <image:caption>A PostgreSQL master password drifted across seven platform types, from Secrets Manager to GitHub, Jenkins, Docker Hub, Jira, Confluence and Slack. Each security tool saw its own si</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/out-of-scope-loophole-credential-exposure</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/3e425fe5a4987e73bed4866083b24733305c7c30-1200x630.png</image:loc>
      <image:title>The &quot;Out of Scope&quot; Loophole: Why Bug Bounties Look Away From Credential Exposure</image:title>
      <image:caption>An organization&apos;s core credentials sat in public repositories for years. The security industry&apos;s answer: &quot;Out of scope.&quot;</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-zombie-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/fabc43b4d2790ff668452a9a360f68e3ef115754-1200x630.png</image:loc>
      <image:title>Expired Credentials That Still Work: The Zombie Key Problem (NHI Kill Chain #5)</image:title>
      <image:caption>Secret scanning alert: Resolved. Credential status: Active. Deleting a secret from code is not the same as revoking it. Inside the Zombie Key kill chain.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-over-shared-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/c48ec8a4ac022136157a7a26048ef52ff3b5a81c-1200x630.png</image:loc>
      <image:title>Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)</image:title>
      <image:caption>A single Stripe API key was copied to 14 locations over three years. When a QA repo went public, the key was exposed, and revoking it meant breaking 14 services at once.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-aged-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/f6e582b5d868160a2c8b611a0c957b932998dcc6-1200x630.png</image:loc>
      <image:title>Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)</image:title>
      <image:caption>A single AWS key, never rotated for 3 years, spread across 7 systems. When a supply chain attack hit a Terraform CI plugin, the key gave attackers full infrastructure access. Insid</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-shadow-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/90791932348f3b36c1c2bd1500246229d206c8dd-1200x630.png</image:loc>
      <image:title>Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)</image:title>
      <image:caption>A single production outage left credentials in six non-code platforms: Slack, Jira, Confluence, Sentry, Datadog and PagerDuty. Your secret scanner found none of them. Inside the Sh</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-ghost-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/4fa791b6c14b0437adcc8ca7adbefb780c70c31b-1200x630.png</image:loc>
      <image:title>Orphaned API Keys: The Security Risk of Credentials With No Owner (NHI Kill Chain #1)</image:title>
      <image:caption>A departed developer&apos;s AWS key stayed active for 92 days. When an infostealer hit their personal laptop, the key was sold on the dark web. Inside the Ghost Key kill chain and how t</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/trivy-supply-chain-attack-kill-chain-analysis</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/0705a3c57569bea327c9cb2bd386f1634ae71828-1200x630.png</image:loc>
      <image:title>When the Security Scanner Became the Weapon: A Cyber Kill Chain Analysis of the Trivy Supply Chain Attack</image:title>
      <image:caption>Aqua Security&apos;s Trivy was compromised by TeamPCP, cascading into LiteLLM. A 7-phase Cyber Kill Chain and MITRE ATT&amp;CK analysis of how incomplete credential rotation turned a single</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi-kill-chain-public-key</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/b550a4defa91e6a11315f1e348e7cf9bf8e53418-1672x941.webp</image:loc>
      <image:title>Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)</image:title>
      <image:caption>A .env file pushed to a public GitHub repo is found by attacker bots in 4 minutes. We map the full kill chain, from credential exposure to infrastructure compromise, and show how t</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/ai-supply-chain-attack-clinejection</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/clinejection-release-path.webp</image:loc>
      <image:title>Clinejection: prompt injection and the unauthorized Cline CLI release</image:title>
      <image:caption>Cline’s issue-triage agent exposed a path to publishing credentials. A later unauthorized CLI release installed OpenClaw; Cline found no user data theft.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/git-secret-scanning-complete-guide-for-2026</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/3538fd5ecc18f21fd8be285d44f681aeb69b2581-2400x1260.png</image:loc>
      <image:title>Git Secret Scanning: Complete Guide for 2026</image:title>
      <image:caption>Complete guide to git secret scanning tools. Compare TruffleHog, GitGuardian, GitHub Advanced Security, and Cremit. Learn implementation strategies with real CI/CD examples</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/api-keys-traded-on-the-dark-web-hackers-new-targe</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/d7fcf6f6d7aa7c40cdaf81278d1da87d62ce72a0-2400x1260.png</image:loc>
      <image:title>API Keys Traded on the Dark Web: Hackers&apos; New Target</image:title>
      <image:caption>API Keys Traded on the Dark Web: Hackers&apos;s New Target</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nx-supply-chain-attack-comprehensive-security-analysis-2025</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/ab10fa69987df758cde5dd18fe8a6f3938bb68b3-2400x1260.png</image:loc>
      <image:title>Nx Package Supply Chain Attack: How a GitHub Actions Vulnerability Caused a Global Crisis</image:title>
      <image:caption>Attackers exploited a GitHub Actions vulnerability to compromise the Nx package. Analysis of the attack chain, who was affected, and how to detect similar threats.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/vercel-secret-exposure-case-study</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/public-deployment-secret.webp</image:loc>
      <image:title>How to Rotate sk_live_, vercel_token, sk-proj Exposed in .env</image:title>
      <image:caption>We found live API keys in 0.45% of public Vercel deployments. AWS credentials, Stripe secrets, GitHub tokens. Here is what exposes them (NEXT_PUBLIC_ misuse is only one), how attac</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/owasp-nhi5-2025---overprivileged-nhi-in-depth-analysis-and-management</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/027179587a7c5190a38cb2b7e9fc5ba5513de65b-2400x1260.png</image:loc>
      <image:title>OWASP NHI5:2025 - Overprivileged NHI In-Depth Analysis and Management</image:title>
      <image:caption>Why service accounts and API keys end up with more privilege than they need, and how A2A and MCP raise the stakes.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/beyond-lifecycle-management-why-continuous-secret-detection-is-non-negotiable-for-nhi-security</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/07087178aca8ae3d31884481f46bea93016cffac-2400x1260.png</image:loc>
      <image:title>Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security</image:title>
      <image:caption>Lifecycle management and scheduled rotation leave a window open. What continuous detection covers inside it.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/owasp-nhi-4-2025</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/e3c2167f621ed9f56524091478b892604d61471a-1672x941.webp</image:loc>
      <image:title>OWASP NHI4:2025 — how to review insecure authentication</image:title>
      <image:caption>Insecure authentication is more than a leaked key. Review OAuth flows, static credentials, token scope, and the rollout path for safer workload access.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/securing-your-software-pipeline-the-role-of-secret-detection</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/d6c0b7d6c30cf8ebfcb8e59d5696fd1647301164-2400x1260.png</image:loc>
      <image:title>CI/CD Pipeline Secret Detection: Preventing Credential Leaks in Build and Deploy</image:title>
      <image:caption>Where credentials leak in modern CI/CD pipelines, what to scan at each stage (pre-commit, build, deploy), and how to integrate secret detection without slowing delivery.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/navigating-the-expanding-ai-universe-deepening-our-understanding-of-mcp-a2a-and-the-imperative-of-non-human-identity-security</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/578e007601c90ab63ce7dccc5d75f49bba7ef891-1672x941.webp</image:loc>
      <image:title>MCP and A2A security: trace the credentials between agents and tools</image:title>
      <image:caption>MCP connects agents to tools; A2A connects agents to each other. Map authentication, token scope, and exposed credentials at every hop.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/stop-secrets-sprawl-shifting-left-for-effective-secret-detection</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/759ffc8d91a41d4bda8781e83278cb3a039dca76-2400x1260.png</image:loc>
      <image:title>Stop Secrets Sprawl: Shifting Left for Effective Secret Detection</image:title>
      <image:caption>Moving secret detection left without slowing delivery. What it costs to catch a key before the commit versus after the deploy.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/hidden-dangers-why-detecting-secrets-in-s3-buckets-is-critical</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/378c81e38ae2f32e6560a3ba22a9f0bc490dfeda-2400x1260.png</image:loc>
      <image:title>Hidden Dangers: Why Detecting Secrets in S3 Buckets is Critical</image:title>
      <image:caption>Credentials ride into S3 buckets alongside backups and config files. How they get there, and why they surface late.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/the-rising-cost-of-data-breaches-how-secret-detection-strengthens-cybersecurity</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/687a1bd21828645dc7e7ea39702cbc2171bc48c3-2400x1260.png</image:loc>
      <image:title>Rising Data Breach Costs: Secret Detection&apos;s Role</image:title>
      <image:caption>Breach costs keep climbing. Which part of that number secret detection actually reduces.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/human-vs-non-human-identity-key-differentiators</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/df0a2503851f175a5b35467c034a950229e3c97e-2400x1260.png</image:loc>
      <image:title>Human vs. Non-Human Identity: The Key Differentiators</image:title>
      <image:caption>Human and machine accounts are issued, owned and revoked differently. Where a single process for both leaves gaps.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/a-wake-up-call-for-nhi-security-the-tj-actions-changed-files-compromise</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/fe4d8c44124a4f9bc4341e91639abae1cf8244e8-2400x1260.png</image:loc>
      <image:title>Wake-Up Call: tj-actions/changed-files Compromised NHIs</image:title>
      <image:caption>A GitHub Action used by more than 23,000 repositories was altered and its version tags retagged, leaking CI/CD secrets into build logs. The incident read as an NHI failure.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi1-2025-improper-offboarding-a-comprehensive-overview</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/f6e011be969af30d2f47bae486a32d07a85c43ed-2400x1260.png</image:loc>
      <image:title>OWASP NHI1:2025 Improper Offboarding- A Comprehensive Overview</image:title>
      <image:caption>Service accounts and tokens that outlive their purpose are the easiest targets in the estate. What OWASP NHI1:2025 says about offboarding.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/stop-the-sprawl-introducing-cremits-aws-s3-non-human-identity-detection</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/6ecbd00af599eec7744b1c44bf678409b32c36b2-2400x1260.png</image:loc>
      <image:title>Stop the Sprawl: Introducing Cremit’s AWS S3 Non-Human Identity Detection</image:title>
      <image:caption>S3 buckets accumulate the machine roles, automated services and API keys that read and write to them. Cremit now scans those buckets continuously with read-only access and returns </image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/build-vs-buy-making-the-right-choice-for-secrets-detection</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/c684fb5eae399853d195d9d9a43a72b6a716d530-2400x1260.png</image:loc>
      <image:title>Build vs. Buy: Making the Right Choice for Secrets Detection</image:title>
      <image:caption>Building secret detection or buying it. The factors that actually decide it, one at a time.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/nhi2-2025-secret-leakage---understanding-and-mitigating-the-risks</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/924d6ccc23ee82daae23d92fc0d93ce5e9f94133-2400x1260.png</image:loc>
      <image:title>OWASP NHI2:2025 Secret Leakage – Understanding and Mitigating the Risks</image:title>
      <image:caption>OWASP NHI2:2025 covers API keys and tokens ending up in stores that were never meant to hold them. Where they leak, and how to stop it.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/the-hidden-danger-in-your-supply-chain-understanding-nhi-threat-3---vulnerable-3rd-party-nhi</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/95e8ead5a09ae313a82743eb68b5f3ef0ee4ff85-2400x1260.png</image:loc>
      <image:title>OWASP NHI3:2025 - Vulnerable Third-Party NHI</image:title>
      <image:caption>Third-party integrations reach into your resources with credentials you never issued. What OWASP NHI3:2025 covers, and where the exposure sits.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/essential-practices-protecting-non-human-identities</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/dbfee76aa2a33919f46631ac2c8dc974a2994d3d-2400x1260.png</image:loc>
      <image:title>6 Essential Practices for Protecting Non-Human Identities</image:title>
      <image:caption>Six practices for keeping credentials out of reach: vaulting, least privilege, rotation and the rest.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/introducing-vigilant-ally</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/59ac1992524d8aac2b3bcba2402c0295d2a33624-2400x1260.png</image:loc>
      <image:title>Vigilant Ally: Helping Developers Secure GitHub Secrets</image:title>
      <image:caption>Vigilant Ally is Cremit’s initiative to help developers find and close the secrets they have exposed on GitHub.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/credential-leakage-risks-hiding-in-frontend-code</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/frontend-bundle-secret.webp</image:loc>
      <image:title>Frontend API Key Leaks: Finding Exposed Secrets in JavaScript Bundles (NEXT_PUBLIC_, .env.local)</image:title>
      <image:caption>JavaScript bundles and source maps routinely leak API keys that never should have reached the browser. Here is how the leak happens, how to find it, and how to stop it.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/cremit-joins-aws-saas-spotlight</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/608735487c85a7786d12d450c483bdad85bb016c-2400x1260.png</image:loc>
      <image:title>Cremit Joins AWS SaaS Spotlight Program</image:title>
      <image:caption>Cremit has joined the AWS SaaS Spotlight program for early-stage SaaS startups in Asia Pacific.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/secret-detection-probe</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/c390418cf9f43e93ad123d325b16d2612035c733-1672x941.webp</image:loc>
      <image:title>Probe to Cremit Platform: what credential scanning does today</image:title>
      <image:caption>An updated guide to Cremit Platform’s scan sources, live credential checks, and remediation workflow, with current product limits.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/devsecops-why-start-with-cremit</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/4536bb2483ccd189e0f4ed1b5e501fb8b2a5cd76-2400x1260.png</image:loc>
      <image:title>DevSecOps starts with a credential your team can actually fix</image:title>
      <image:caption>A practical rollout for credential detection across repositories and collaboration tools, with clear owners and honest scan timing.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/enlighten-interview</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/a6027907e1a2bda9d5d0f0d2c7e427e7d0801bfc-2400x1260.png</image:loc>
      <image:title>Customer Interview: Insights from ENlighten</image:title>
      <image:caption>A conversation with the team at ENlighten, a Korean energy IT platform, about how they manage credentials and secrets and what led them to Cremit.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/what-is-secret-detection-a-beginners-guide-to-securing-sensitive-information</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/3dcf6916564afcf2a252d839dfbc703c8f351907-2400x1260.png</image:loc>
      <image:title>What Is Secret Detection? A Beginner’s Guide</image:title>
      <image:caption>What secret detection is, how it works, and what it looks at across code, containers and cloud workloads.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/microsoft-leaked-secrets</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/f19bcbced302f2a9818671fe3de3ee1aeb044d98-2400x1260.png</image:loc>
      <image:title>Microsoft Secrets Leak: A Cybersecurity Wake-Up Call</image:title>
      <image:caption>One misconfigured SAS token in a Microsoft AI research repository exposed 30,000 internal Teams messages. How it happened.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/secret-sprawl-and-non-human-identities-the-growing-security-challenge</loc>
    <image:image>
      <image:loc>https://cdn.sanity.io/images/iwjcunsj/production/42d6429aeb96c2184e2cd92eeeb267e41fe5c39f-2400x1260.png</image:loc>
      <image:title>Secret Sprawl and Non-Human Identities: The Growing Security Challenge</image:title>
      <image:caption>Secret sprawl stopped being a password problem and became an identity one. Where credentials accumulate, and what detection actually reduces.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/bybit-hacking-incident-analysis-how-to-strengthen-cryptocurrency-exchange-security</loc>
    <image:image>
      <image:loc>https://www.cremit.io/images/blog/bybit-safe-wallet-transaction.webp</image:loc>
      <image:title>Bybit Hack: What the Safe Wallet Investigation Found</image:title>
      <image:caption>The February 2025 theft involved a compromised Safe developer and a manipulated transaction interface. Here is what investigators confirmed and what remains unknown.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/slack-alarm</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/slack-alarm/opengraph-image</image:loc>
      <image:title>Slack: Cremit integration</image:title>
      <image:caption>Send detection alerts to a Slack channel via OAuth-installed Cremit Platform.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/webhook</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/webhook/opengraph-image</image:loc>
      <image:title>Webhook: Cremit integration</image:title>
      <image:caption>POST JSON payloads to any HTTPS endpoint: your SOAR, Discord, or a relay into PagerDuty and Teams.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/telegram</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/telegram/opengraph-image</image:loc>
      <image:title>Telegram: Cremit integration</image:title>
      <image:caption>Deliver alerts to a Telegram channel or group via bot token.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/aws-cloudformation</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/aws-cloudformation/opengraph-image</image:loc>
      <image:title>AWS (CloudFormation): Cremit integration</image:title>
      <image:caption>Deploy a read-only analyzer via CloudFormation to map IAM permissions attached to discovered AWS credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/gcp-service-account</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/gcp-service-account/opengraph-image</image:loc>
      <image:title>GCP (Service Account): Cremit integration</image:title>
      <image:caption>Connect a read-only service account to map IAM bindings and roles on discovered GCP credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/github</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/github/opengraph-image</image:loc>
      <image:title>GitHub: Cremit integration</image:title>
      <image:caption>Scan repositories, commit history, issues, and GHCR container images for exposed secrets across your GitHub organization.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/gitlab</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/gitlab/opengraph-image</image:loc>
      <image:title>GitLab: Cremit integration</image:title>
      <image:caption>Scan self-hosted or SaaS GitLab projects, commit history, and issues for credential exposure.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/aws-s3</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/aws-s3/opengraph-image</image:loc>
      <image:title>AWS S3: Cremit integration</image:title>
      <image:caption>Scan S3 buckets for credentials, API keys, and tokens stored in object storage.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/bitbucket</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/bitbucket/opengraph-image</image:loc>
      <image:title>Bitbucket: Cremit integration</image:title>
      <image:caption>Scan the commit history of every repository in a Bitbucket Cloud workspace for exposed credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/google-drive</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/google-drive/opengraph-image</image:loc>
      <image:title>Google Drive: Cremit integration</image:title>
      <image:caption>Scan documents, spreadsheets, and shared drives for pasted credentials, API keys, and tokens.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/jira</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/jira/opengraph-image</image:loc>
      <image:title>Jira: Cremit integration</image:title>
      <image:caption>Scan Jira issue descriptions, comments, and attachments for pasted credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/confluence</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/confluence/opengraph-image</image:loc>
      <image:title>Confluence: Cremit integration</image:title>
      <image:caption>Scan Confluence pages, templates, and attachments for credentials stored in documentation.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/notion</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/notion/opengraph-image</image:loc>
      <image:title>Notion: Cremit integration</image:title>
      <image:caption>Scan Notion workspace pages and databases for pasted API keys, tokens, and credentials.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/slack-scan</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/slack-scan/opengraph-image</image:loc>
      <image:title>Slack (Messages): Cremit integration</image:title>
      <image:caption>Scan Slack channels and DMs for pasted credentials, API keys, and tokens.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/scim-okta</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/scim-okta/opengraph-image</image:loc>
      <image:title>Okta SCIM: Cremit integration</image:title>
      <image:caption>Auto-provision and de-provision Cremit Platform users from Okta groups. Handles onboarding and offboarding.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/scim-google-workspace</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/scim-google-workspace/opengraph-image</image:loc>
      <image:title>Google Workspace SCIM: Cremit integration</image:title>
      <image:caption>Sync Google Workspace users and groups to Cremit Platform. Automatic access removal when accounts are suspended.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations/saml-sso</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/saml-sso/opengraph-image</image:loc>
      <image:title>SAML 2.0: Cremit integration</image:title>
      <image:caption>Authenticate users through your SAML 2.0 IdP (Okta, Azure AD, Google Workspace, Ping, etc.).</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/integrations</loc>
    <image:image>
      <image:loc>https://www.cremit.io/integrations/opengraph-image</image:loc>
      <image:title>Cremit Platform Integrations</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.cremit.io/blog/series/nhi-kill-chain</loc>
    <image:image>
      <image:loc>https://www.cremit.io/blog/series/nhi-kill-chain/opengraph-image</image:loc>
      <image:title>NHI Kill Chain Series</image:title>
    </image:image>
  </url>
</urlset>