AI Autonomy: How to Find the Autonomy Your Agents Already Have
AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.
Service Account Credential Rotation: The Blast-Radius Checklist
A practical checklist for rotating service account credentials safely by assessing validity, leaks, permissions, consumers, vaults, copies, owners, and rollback.
OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome
Learn how the OWASP Top 10 CI/CD Security Risks map the modern software delivery attack surface, and why credential hygiene sits at the center of so many real-world failures.
AWS S3 Bucket Security: Find the Secrets Hiding Outside Git
S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.
AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection
AI agent threat response starts before runtime. See why pre-runtime credential controls stop agent misuse that runtime detection can only observe.
Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between credential theft and abuse
BSides Las Vegas 2026: Following the Trust Relationships Attackers Are Targeting
BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it.
Vault Coverage Is the Missing Metric in NHI Programs
Most vault programs track a numerator without a denominator. See how vault coverage turns secrets management into a measurable, reportable control.
IEEE Cloud Summit 2026: The Tunnels No One Mapped
Explore cloud security lessons from IEEE Cloud Summit 2026, including agentic AI risks, over-permissioned identities, Kubernetes policy, and forensics.
AI Is the Newest Developer To Misunderstand Secrets In Your Git History
AI assistants are repeating a common Git mistake: committing fixes that remove secrets only from the latest code, not from repository history. GitGuardian AI Skills can help.
Identiverse 2026: The Challenges Of Solving Identity For AI Agents At Scale
This year's event made it clear that as AI agents scale across enterprises, we must solve ownership, delegation, least privilege, and auditability before production risk grows.
BSides San Antonio 2026: Following Trust Across Applications, Cloud, and Compliance
Sessions at BSidesSATX 2026 connected runtime secrets, cloud identity permissions, compliance evidence, and, ultimately, the human side of security.