{
  "id": 12892055,
  "title": "Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders",
  "url": "https://urgent.news/2026/10/08/public-secrets-monitoring-find-a-credential-leak-beyond-your-borders",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T15:07:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/gitguardian/public-secrets-monitoring-find-a-credential-leak-beyond-your-borders-52m4"
  },
  "original_language": "en",
  "account": "Credential leak on a massive scale: GitGuardian finds 28.65 million hardcoded secrets in public GitHub commits in 2025, a 34% jump from the previous year. Almost 80% of corporate leaks traced back to developers' personal repositories, a risk highlighted by the CISA leak discovered in May 2026. GitGuardian's Public Monitoring capabilities give security and DevSecOps teams a clear, actionable answer to the question of which company credentials are exposed in public development activity. This visibility extends beyond the company-owned repositories, scanning every public GitHub commit since 2017 and all private commits that became public. The findings show that nearly 80% of corporate credential leaks detected on GitHub occurred in developers' personal repositories, a blind spot that GitGuardian aims to address.",
  "summary": "TL;DR A credential leak far beyond company walls: 28.65 million new hardcoded secrets in public GitHub commits in 2025 (up 34%), and almost 80% of one customer's corporate leaks traced back to developers' personal repositories, a risk echoed by the CISA leak found in May 2026. New verdicts cut through the noise: GitGuardian's Agents Analysis now cleanly labels each public incident, reorganizing…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}