<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>GitGuardian: The Credential Layer Security Platform, helping enterprises close credential-based breach paths.&#xA;&#xA;&#xA;Website: gitguardian.com&#xA;Blog: blog.gitguardian.com&#xA;Free GH audit: s.gitguardian.com/free-audit</description><link>https://bsky.app/profile/gitguardian.com</link><title>@gitguardian.com - GitGuardian</title><item><link>https://bsky.app/profile/gitguardian.com/post/3mo3qmdhsv22x</link><description>A historical scan can surface hundreds or thousands of incidents at once. GitGuardian&#39;s incident table is built to answer what to work on first: verified validity, automated severity scoring across 24 rule sets, and saved filtered views. &#xA;&#xA;youtu.be/Fhj83rW1lOQ&#xA;https://youtu.be/Fhj83rW1lOQ</description><pubDate>12 Jun 2026 12:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mo3qmdhsv22x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnwo5dwarc2r</link><description>ggshield can plant honey tokens directly from your terminal. Decoy AWS keys that look real, grant no access, and alert you the moment someone tries to use them. Trip wires for your codebase. &#xA;&#xA;youtu.be/UsLGa44CugM&#xA;https://youtu.be/UsLGa44CugM</description><pubDate>10 Jun 2026 12:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnwo5dwarc2r</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnufigmunc2r</link><description>GitGuardian now scans Gerrit. Full historical scan on connect, real-time scanning on every new commit and comment. Findings land in the same dashboard as your GitHub, GitLab, and Bitbucket incidents. &#xA;&#xA;youtu.be/q1XzY6HvxAI&#xA;https://youtu.be/q1XzY6HvxAI</description><pubDate>09 Jun 2026 14:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnufigmunc2r</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnrmxbgcgc2n</link><description>AI coding assistants read files, run commands, and call tools. ggshield AI hooks scan at each of those points and block secrets before they reach prompts, logs, or generated code. One install command. Works with Cursor, Claude Code, and Copilot. &#xA;&#xA;youtu.be/he0Ynu32puQ&#xA;https://youtu.be/he0Ynu32puQ</description><pubDate>08 Jun 2026 11:58 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnrmxbgcgc2n</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnkcmfh33s2q</link><description>GitGuardian&#39;s updated search bar lets you triage incidents by pasting a secret value, typing an author email, a file path, or plain language like &#34;open critical unassigned cloud incidents.&#34; Available now on every plan. &#xA;&#xA;youtu.be/LSrBUCvJaLM&#xA;https://youtu.be/LSrBUCvJaLM</description><pubDate>05 Jun 2026 14:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnkcmfh33s2q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnhsrvnpk22q</link><description>When a breach happens, you need to account for every secret: which were in CI, which were on developer laptops, which processes had access. &#xA;&#xA;That inventory is what you show your board. &#xA;&#xA;https://youtube.com/shorts/EOrZmlsTsE0</description><pubDate>04 Jun 2026 14:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnhsrvnpk22q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnfspgd2xc2q</link><description>When an LLM hits a security constraint, GitGuardian research shows it often goes around it, silently, and hardcodes the secret. &#xA;&#xA;The developer didn&#39;t make that call. The model did. https://youtube.com/shorts/999wS_fyBhg</description><pubDate>03 Jun 2026 19:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnfspgd2xc2q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mncoqf3jcc2h</link><description>GitGuardian&#39;s VS Code extension now shows all secret findings in a sidebar panel — across every file, before you commit. Works in Cursor and Windsurf too. Catch it on save, not in CI. youtu.be/d18uYyOhez8&#xA;https://youtu.be/d18uYyOhez8</description><pubDate>02 Jun 2026 13:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mncoqf3jcc2h</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mnaggtzlrs2h</link><description>One stolen PAT in February. Trivy poisoned March 19. &#xA;Eight days later: Aqua, Checkmarx, LiteLLM, and Telnyx all compromised because they automatically consumed the update. &#xA;This is what supply chain cascade looks like. https://youtube.com/shorts/qa-47teRcW8</description><pubDate>01 Jun 2026 15:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mnaggtzlrs2h</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mmylgl2zos2h</link><description>ggshield 1.51: AI hooks now cover Codex alongside #Claude, #ChatGPT, and #Cursor. &#xA;#MCP server discovery extended to plugin-installed servers. &#xA;&#xA;Plus oob (out-of-band) auth, better SLSA provenance, and improved API status. &#xA;youtu.be/RCIeYF3nkn0&#xA;https://youtu.be/RCIeYF3nkn0</description><pubDate>29 May 2026 12:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mmylgl2zos2h</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mmw2fkvcbc2q</link><description>Claude Code co-authored commits leak secrets at 2.4× the human baseline. Larger commits, more lines, more exposure surface. AI speeds up development — and quietly expands the attack surface. &#xA;&#xA;https://youtube.com/shorts/9jEDlkMoVX0</description><pubDate>28 May 2026 12:44 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mmw2fkvcbc2q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mmtlkleva22q</link><description>Claude Code co-authored commits leak secrets at 2.4× the human baseline. Larger commits, more lines, more exposure surface. AI speeds up development — and quietly expands the attack surface. https://youtube.com/shorts/9jEDlkMoVX0</description><pubDate>27 May 2026 13:13 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mmtlkleva22q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mmeg6mzwd22q</link><description>A CISA contractor pushed AWS GovCloud admin keys to a public GitHub repo in November. It sat there for 6 months, after GitGuardian sent 7–10 alerts. &#xA;No response. &#xA;&#xA;Guillaume Valadon walks us through how we escalated this disclosure: &#xA;youtu.be/mWIgasN3K7Q&#xA;https://youtu.be/mWIgasN3K7Q</description><pubDate>21 May 2026 12:27 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mmeg6mzwd22q</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mmbwkcf5rc2x</link><description>Exploiting a vulnerability targets production. Malware targets the developer. &#xA;That&#39;s not a subtle difference: it&#39;s where the credentials live: https://youtube.com/shorts/2-9e4MVy6xM</description><pubDate>20 May 2026 12:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mmbwkcf5rc2x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mm4vp6fuzc23</link><description>75,000 open incidents is normal for GitGuardian customers. &#xA;&#xA;A &#34;generic IAM copy&#34; enriched to &#34;Microsoft credential, publicly leaked&#34; = risk score 100. &#xA;&#xA;That&#39;s ML-powered triage in practice: youtu.be/iyKHvK3g9g8&#xA;https://youtu.be/iyKHvK3g9g8</description><pubDate>18 May 2026 12:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mm4vp6fuzc23</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlvgsge7dk2x</link><description>After a developer machine compromise: what secrets were exposed, where, and what needs rotation now? &#xA;&#xA;GitGuardian Developer Endpoint Protection scans your fleet via MDM and answers all three: youtu.be/IDzSiJQCZZA&#xA;https://youtu.be/IDzSiJQCZZA</description><pubDate>15 May 2026 13:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlvgsge7dk2x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlsx2wmuwc2o</link><description>Every time a developer pushes a secret to public GitHub, GitGuardian emails them directly. &#xA;&#xA;That&#39;s the Good Samaritan program. Millions of alerts sent per year: &#xA;&#xA;https://youtube.com/shorts/dUzjIpf3FTI</description><pubDate>14 May 2026 13:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlsx2wmuwc2o</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlqegw7r7c2o</link><description>Gerrit is one of the most widely deployed code review platforms in enterprise environments, yet a blind spot for secrets detection. &#xA;&#xA;GitGuardian now scans it, historically and in real time: &#xA;&#xA;youtu.be/q1XzY6HvxAI&#xA;https://youtu.be/q1XzY6HvxAI</description><pubDate>13 May 2026 13:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlqegw7r7c2o</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlnrvtkya22f</link><description>.env files are plain text secrets on a machine that&#39;s a supply chain target. &#xA;&#xA;ggshield 1.50 moves API tokens to your OS credential store by default and extends AI hooks to the MCP layer. &#xA;&#xA;Full breakdown: youtu.be/4c983T8hAyc&#xA;https://youtu.be/4c983T8hAyc</description><pubDate>12 May 2026 12:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlnrvtkya22f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mllcfz7qg22f</link><description>Cmd+K from anywhere in GitGuardian and jump to incidents, settings, integrations, or docs without leaving your workspace. &#xA;&#xA;Context-aware, role-scoped. &#xA;&#xA;Small thing, saves real time mid-incident: &#xA;&#xA;youtu.be/Jx-RpuMX7ak&#xA;https://youtu.be/Jx-RpuMX7ak</description><pubDate>11 May 2026 12:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mllcfz7qg22f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mldwkmq3nk2r</link><description>Ask GitGuardian &#34;what are my top 10 public incidents right now?&#34; and it answers. &#xA;&#xA;Natural language triage against all your incidents, in-app. &#xA;&#xA;Same 23 tools as the MCP server. &#xA;&#xA;Full demo: youtu.be/AqVPvAjkGR0&#xA;https://youtu.be/AqVPvAjkGR0</description><pubDate>08 May 2026 14:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mldwkmq3nk2r</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mf2tea74ms24</link><description>90B events/day and we’re still manually doing L1 triage? &#xA;That’s not resilience, that’s ✨tradition✨.&#xA;&#xA;#ChiBrrCon 2026 takeaway: automate the repetitive, keep humans for judgment, and build real inventories.&#xA;&#xA;#AppSec #AI&#xA;&#xA;https://blog.gitguardian.com/chibrrcon-2026/</description><pubDate>17 Feb 2026 15:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mf2tea74ms24</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mdnomx6owk25</link><description>🤖 Agents don’t log in. They act.&#xA;At #NHIcon 2026 the message was clear: human-centric IAM breaks in the age of agentic AI.&#xA;Static roles + long-lived creds = 🚨 risk amplification.&#xA;Time for identity at the speed of autonomy. 🔐&#xA;blog.gitguardian.com/nhicon-2026&#xA;https://blog.gitguardian.com/nhicon-2026</description><pubDate>30 Jan 2026 16:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mdnomx6owk25</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mczhlylcac25</link><description>Secrets sprawl ≠ developer mistakes.&#xA;It’s unmanaged machine access at scale.&#xA;Boards care about downtime, cost, and resilience, and NHIs sit right in the middle.&#xA;Here’s how to connect the dots 👇&#xA;&#xA;https://blog.gitguardian.com/boards-focus-on-risks-nhi-governance</description><pubDate>22 Jan 2026 15:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mczhlylcac25</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mcabxcbmck2f</link><description>AI agents aren’t your coworkers.&#xA;They’re over-permissioned bots with access to prod. Stop pretending they’re cute. Start treating them like risks.&#xA;🛑&#xA;NHI governance now! &#xA;&#xA;https://blog.gitguardian.com/what-ai-agents-can-teach-us-about-nhi-governance/</description><pubDate>12 Jan 2026 14:49 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mcabxcbmck2f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mbtxpumhpk2h</link><description>AI agents are already causing incidents, and identity controls aren’t ready.&#xA;&#xA;Jan 27: Join GitGuardian at #NHIcon2026. &#xA;&#xA;Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social &#xA;&#xA;Free registration here: https://aembit.io/nhicon?aff=GitGuardian</description><pubDate>07 Jan 2026 17:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mbtxpumhpk2h</guid></item></channel></rss>