<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>GitGuardian leads the way in Non-Human Identity security, offering end-to-end solutions.&#xA;&#xA;Website: gitguardian.com&#xA;Blog: blog.gitguardian.com&#xA;Free GH audit: s.gitguardian.com/free-audit</description><link>https://bsky.app/profile/gitguardian.com</link><title>@gitguardian.com - GitGuardian</title><item><link>https://bsky.app/profile/gitguardian.com/post/3mlvgsge7dk2x</link><description>After a developer machine compromise: what secrets were exposed, where, and what needs rotation now? &#xA;&#xA;GitGuardian Developer Endpoint Protection scans your fleet via MDM and answers all three: youtu.be/IDzSiJQCZZA&#xA;https://youtu.be/IDzSiJQCZZA</description><pubDate>15 May 2026 13:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlvgsge7dk2x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlsx2wmuwc2o</link><description>Every time a developer pushes a secret to public GitHub, GitGuardian emails them directly. &#xA;&#xA;That&#39;s the Good Samaritan program. Millions of alerts sent per year: &#xA;&#xA;https://youtube.com/shorts/dUzjIpf3FTI</description><pubDate>14 May 2026 13:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlsx2wmuwc2o</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlqegw7r7c2o</link><description>Gerrit is one of the most widely deployed code review platforms in enterprise environments, yet a blind spot for secrets detection. &#xA;&#xA;GitGuardian now scans it, historically and in real time: &#xA;&#xA;youtu.be/q1XzY6HvxAI&#xA;https://youtu.be/q1XzY6HvxAI</description><pubDate>13 May 2026 13:03 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlqegw7r7c2o</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mlnrvtkya22f</link><description>.env files are plain text secrets on a machine that&#39;s a supply chain target. &#xA;&#xA;ggshield 1.50 moves API tokens to your OS credential store by default and extends AI hooks to the MCP layer. &#xA;&#xA;Full breakdown: youtu.be/4c983T8hAyc&#xA;https://youtu.be/4c983T8hAyc</description><pubDate>12 May 2026 12:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mlnrvtkya22f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mllcfz7qg22f</link><description>Cmd+K from anywhere in GitGuardian and jump to incidents, settings, integrations, or docs without leaving your workspace. &#xA;&#xA;Context-aware, role-scoped. &#xA;&#xA;Small thing, saves real time mid-incident: &#xA;&#xA;youtu.be/Jx-RpuMX7ak&#xA;https://youtu.be/Jx-RpuMX7ak</description><pubDate>11 May 2026 12:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mllcfz7qg22f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mldwkmq3nk2r</link><description>Ask GitGuardian &#34;what are my top 10 public incidents right now?&#34; and it answers. &#xA;&#xA;Natural language triage against all your incidents, in-app. &#xA;&#xA;Same 23 tools as the MCP server. &#xA;&#xA;Full demo: youtu.be/AqVPvAjkGR0&#xA;https://youtu.be/AqVPvAjkGR0</description><pubDate>08 May 2026 14:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mldwkmq3nk2r</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mf2tea74ms24</link><description>90B events/day and we’re still manually doing L1 triage? &#xA;That’s not resilience, that’s ✨tradition✨.&#xA;&#xA;#ChiBrrCon 2026 takeaway: automate the repetitive, keep humans for judgment, and build real inventories.&#xA;&#xA;#AppSec #AI&#xA;&#xA;https://blog.gitguardian.com/chibrrcon-2026/</description><pubDate>17 Feb 2026 15:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mf2tea74ms24</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mdnomx6owk25</link><description>🤖 Agents don’t log in. They act.&#xA;At #NHIcon 2026 the message was clear: human-centric IAM breaks in the age of agentic AI.&#xA;Static roles + long-lived creds = 🚨 risk amplification.&#xA;Time for identity at the speed of autonomy. 🔐&#xA;blog.gitguardian.com/nhicon-2026&#xA;https://blog.gitguardian.com/nhicon-2026</description><pubDate>30 Jan 2026 16:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mdnomx6owk25</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mczhlylcac25</link><description>Secrets sprawl ≠ developer mistakes.&#xA;It’s unmanaged machine access at scale.&#xA;Boards care about downtime, cost, and resilience, and NHIs sit right in the middle.&#xA;Here’s how to connect the dots 👇&#xA;&#xA;https://blog.gitguardian.com/boards-focus-on-risks-nhi-governance</description><pubDate>22 Jan 2026 15:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mczhlylcac25</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mcabxcbmck2f</link><description>AI agents aren’t your coworkers.&#xA;They’re over-permissioned bots with access to prod. Stop pretending they’re cute. Start treating them like risks.&#xA;🛑&#xA;NHI governance now! &#xA;&#xA;https://blog.gitguardian.com/what-ai-agents-can-teach-us-about-nhi-governance/</description><pubDate>12 Jan 2026 14:49 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mcabxcbmck2f</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3mbtxpumhpk2h</link><description>AI agents are already causing incidents, and identity controls aren’t ready.&#xA;&#xA;Jan 27: Join GitGuardian at #NHIcon2026. &#xA;&#xA;Talk: “How Agentic AI Helps You Leak Secrets (and What to Do About It)” (1 PM PST, Builders Track) w/ @mdwayne-real.bsky.social &#xA;&#xA;Free registration here: https://aembit.io/nhicon?aff=GitGuardian</description><pubDate>07 Jan 2026 17:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3mbtxpumhpk2h</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3madeuntboc2p</link><description>Andy Rea built a demo showing how to wire up multiple AI agents using Google&#39;s Agent Development Kit (ADK) and the #A2A protocol, with GitGuardian scanning content for secrets. &#xA;https://blog.gitguardian.com/building-a-multi-agent-security-pipeline-with-googles-a2a-protocol-and-gitguardian/&#xA;&#xA;The complete code is available at: https://github.com/reaandrew/a2a-demo</description><pubDate>19 Dec 2025 09:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3madeuntboc2p</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3ma6xnjoiu22m</link><description>🚀 The future of secure non‑human identity is here!  &#xA;&#xA;AWS IAM Outbound Identity Federation eliminates long‑term creds in favor of short‑lived tokens.&#xA;&#xA;GitGuardian can help you track the migration in real time. &#xA;&#xA;https://blog.gitguardian.com/aws-iam-outbound-identity-federation-with-gitguardian/&#xA;&#xA;#DevSecOps #AppSec</description><pubDate>17 Dec 2025 15:21 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3ma6xnjoiu22m</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m7at536sa22s</link><description>Secrets leaked? Don’t panic—push to vault! 🧯&#xA;GitGuardian&#39;s Push-to-Vault turns “uh-oh” into “handled” by sending secrets straight into your existing Secret Manager.&#xA;No more tab juggling.&#xA;blog.gitguardian.com/push-to-vault/&#xA;https://blog.gitguardian.com/push-to-vault/</description><pubDate>05 Dec 2025 15:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m7at536sa22s</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m73v6o7x5s2s</link><description>🔄 Feature flags, legacy systems, and N+1 queries walk into a dev conf... /dev/mtl 2025 reminds us: it’s not about speed, it’s about smart feedback loops. &#xA;#DevSecOps &#xA;blog.gitguardian.com/dev-mtl-2025/&#xA;https://blog.gitguardian.com/dev-mtl-2025/</description><pubDate>03 Dec 2025 16:34 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m73v6o7x5s2s</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m6oukajid22z</link><description>🚨 #Shai_Hulud  techincal analysis is live&#xA;We&#39;ve completed our forensic analysis of the Nov 24 supply chain attack. 754 infected npm packages, 20,649 analyzed repositories, 33,185 unique secrets (3,760 valid).&#xA;blog.gitguardian.com/shai-hulud-2/</description><pubDate>28 Nov 2025 12:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m6oukajid22z</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m6f4ccfaxk2l</link><description>🔐 The 2025 #OWASP Top 10 2025 says it loud: &#xA;access control still #1, but now supply chains &amp; mis‑configs steal the spotlight. &#xA;Ready your CI/CD, stacks &amp; cloud.&#xA;&#xA;https://blog.gitguardian.com/owasp-top-10-2025/&#xA;&#xA;#AppSec #DevSecOps</description><pubDate>24 Nov 2025 15:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m6f4ccfaxk2l</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m65lenz7z22l</link><description>🔐 From “API keys in Git” to “agentic AI with scoped identities” — the next frontier of security is non‑human actors with strong attestation. #DevSecOps #CloudNative #CyberArk #SPIFFE &#xA;#KubeCon &#xA;&#xA;https://blog.gitguardian.com/workload-identity-day-zero-atlanta</description><pubDate>21 Nov 2025 15:19 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m65lenz7z22l</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m633fpd3e22l</link><description>Containers were the on‑ramp, not the destination.” At #KubeCon 2025 identity, governance &amp; agent security stole the show. Microservices + AI = new risk surface. &#xA;Read more: blog.gitguardian.com/kubecon-2025&#xA;https://blog.gitguardian.com/kubecon-2025</description><pubDate>20 Nov 2025 15:27 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m633fpd3e22l</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m4xv6lf4wk2a</link><description>🚨 Identity is the new perimeter. At #BSidesChicago 2025 we saw attackers moving through the cloud control‑plane like it’s tourist season — service principals &amp; Kubernetes misconfigs are their playground. 🍿 Dive deeper: &#xA;https://blog.gitguardian.com/bsides-chicago-2025/&#xA;&#xA;#DevSecOps #AppSec</description><pubDate>06 Nov 2025 15:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m4xv6lf4wk2a</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m4styreia22a</link><description>At #TechnoSecurity West 2025, identity = perimeter. &#xA;If your IAM is a maze,  attackers have already found the exit. &#xA;🧩🔐 &#xA;https://blog.gitguardian.com/techno-security-and-digital-forensics-conference-west-2025/</description><pubDate>04 Nov 2025 15:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m4styreia22a</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m4iug4yuck2a</link><description>Human admins aren’t the only VIPs; service accounts and automation scripts need the spotlight too. &#xA;&#xA;👀 &#xA;&#xA;Read how GitGuardian helps you widen the scope of PAM and kill secret sprawl for good. &#xA;&#xA;https://blog.gitguardian.com/working-towards-improved-pam-widening-the-scope-and-taking-control/&#xA;&#xA; #AppSec #SecOps</description><pubDate>31 Oct 2025 16:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m4iug4yuck2a</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m3pj4sjzmc2x</link><description>🚀 At #INCYBERCanada 2025 in Montréal we heard loud &amp; clear: compliance doesn’t cut it anymore—collaboration is the new security foundation. 🌐 Let’s govern machine identities, secure our global supply‑chains, and build resilience together.&#xA;&#xA;https://blog.gitguardian.com/incyber-forum-canada-2025/</description><pubDate>21 Oct 2025 14:11 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m3pj4sjzmc2x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m3pgdm2zzk2x</link><description>Back to security basics at CornCon 11: Why resilience beats perfection&#xA;&#xA;The big takeaway: &#xA;Embrace sustainable security programmes – don’t chase zero‑risk illusions, build something you can maintain.&#xA;&#xA;Read more: blog.gitguardian.com/corncon-11/&#xA;https://blog.gitguardian.com/corncon-11/</description><pubDate>21 Oct 2025 13:21 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m3pgdm2zzk2x</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3m2cicle5ws2s</link><description>GitHub is doubling down: requiring WebAuthn, OIDC, and ultra-short tokens to harden npm publishing. These aren’t just npm rules — they’re lessons for all devs. 🔐 &#xA;&#xA;https://blog.gitguardian.com/security-lessons-npm-publishing/&#xA;&#xA;#DevSecOps #SupplyChainSecurity</description><pubDate>03 Oct 2025 16:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3m2cicle5ws2s</guid></item><item><link>https://bsky.app/profile/gitguardian.com/post/3lz6zznlu6k2s</link><description>Who owns your API keys? &#xA;Spoiler: probably not the person you think &#xA;&#xA;😅 Stop playing hot potato with NHIs—focus on context, not blame.&#xA;👉   https://blog.gitguardian.com/defining-nhi-ownership/&#xA;&#xA;#OWASP #NHIs #MachineIdentities</description><pubDate>19 Sep 2025 14:07 +0000</pubDate><guid isPermaLink="false">at://did:plc:vp7sdwxtge3xj2dtowoedctm/app.bsky.feed.post/3lz6zznlu6k2s</guid></item></channel></rss>