Urgent.News

What's breaking now, across thousands of outlets.

Tech

Generative AI Security: Are Your Developers Pasting Secrets Into LLMs?

TL;DR 81% jump in AI-service leaks : GitGuardian detected over 1.27 million leaked secrets tied to AI services in 2025, an 81% jump from the previous year, with AI-assisted code leaking secrets at roughly twice the GitHub-wide rate. Hundreds of incidents in weeks : One customer deployed GitGuardian behind their internal AI gateway and surfaced hundreds of secret incidents within weeks, a…

The number of leaked secrets tied to AI services jumped 81% in 2025, with GitGuardian detecting over 1.27 million such secrets, compared to an 18% increase across all GitHub repositories. This jump comes as AI-assisted code leaks secrets at roughly twice the rate of traditional code. One customer deployed GitGuardian behind their internal AI gateway and uncovered hundreds of secret incidents in just weeks, all occurring before the secrets ever reached a git repository.

These incidents came from developers pasting curl commands, .env files, and config files into AI prompts or tools without reviewing the full content. While prompt traffic is newer and less covered, secrets detection for code has matured, with tools like ggshield AI Hooks scanning prompts and blocking leaks. However, AI prompts remain a weak spot, needing both pre-commit (AI Hooks) and pre-receive (AI gateway) controls.

AI prompts pose unique challenges: they leave the organization's perimeter immediately, go to a third party with retention terms beyond the organization's control, and are gone as soon as sent unless captured. An internal AI gateway, acting as an LLM proxy or gateway, sees every prompt and response and is the ideal place to scan this traffic.

By forwarding payloads to GitGuardian's scan API and blocking or non-blocking requests based on findings, organizations can measure exposure and enforce security.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What Is HTTP/3? Why Most of the Web Still Isn't Using It

Every major browser decided HTTP/3 was ready years ago. Chrome, Edge, Firefox and Safari have all shipped full support since 2022, and caniuse.com puts global browser support at 94.55% as of October…

  • Only 40.8% of websites serve pages over HTTP/3 as of October 2026
  • Browser support for HTTP/3 sits at 94.55% globally
  • Server configuration and corporate firewalls block UDP traffic needed for QUIC

AccessBuild Day 3: Auto-Scanning Is Live. Here's What I Learned.

Day 3 of AccessBuild. The API is no longer just a calculator. It has a memory now. What I Built Today Yesterday, the API could only score elements you pasted in manually.

  • Auto-scan feature added to AccessBuild API
  • /scan endpoint processes UI tree dumps for accessibility analysis
  • Grade D received by test banking login screen audit

More from Tuesday 6 October →