• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2026-2027
  • Sponsored Post
  • Market Reports
  • About
    • GDPR
  • Contact

GitGuardian Report: 70% of Leaked Secrets Remain Active for Two Years, Urging Immediate Remediation

March 11, 2025 By CyberNewswire Leave a Comment

Boston, USA, March 11th, 2025, CyberNewsWire

GitGuardian, the security leader behind GitHub’s most installed application, today released its comprehensive “2025 State of Secrets Sprawl Report,” revealing a widespread and persistent security crisis that threatens organizations of all sizes. The report exposes a 25% increase in leaked secrets year-over-year, with 23.8 million new credentials detected on public GitHub in 2024 alone.

Most concerning for enterprise security leaders: 70% of secrets leaked in 2022 remain active today, creating an expanding attack surface that grows more dangerous with each passing day.

“The explosion of leaked secrets represents one of the most significant yet underestimated threats in cybersecurity,” said Eric Fourrier, CEO of GitGuardian. “Unlike sophisticated zero-day exploits, attackers don’t need advanced skills to exploit these vulnerabilities—just one exposed credential can provide unrestricted access to critical systems and sensitive data.”

Eric Fourrier points to the 2024 U.S. Treasury Department breach as a warning: “A single leaked API key from BeyondTrust allowed attackers to infiltrate government systems. This wasn’t a sophisticated attack—it was a simple case of an exposed credential that bypassed millions in security investments.”

Key Findings for Security Leaders

The report identifies several critical trends that demand immediate attention:

The Blind Spot: Generic Secrets

Despite GitHub’s Push Protection helping developers detect known secret patterns, generic secrets—including hardcoded passwords, database credentials, and custom authentication tokens—now represent more than half of all detected leaks. These credentials lack standardized patterns, making them nearly impossible to detect with conventional tools.

Private Repositories: A False Sense of Security

The analysis reveals a startling truth: a full 35% of all private repositories scanned contained at least one plaintext secret, shattering the common assumption that private repositories are secure:

  • AWS IAM keys appeared in plaintext in 8.17% of private repositories—over 5× more frequently than in public ones (1.45%)
  • Generic passwords appeared nearly 3× more often in private repositories (24.1%) compared to public ones (8.94%)
  • MongoDB credentials were the most frequently leaked secret type in public repositories (18.84%)

“Leaked secrets in private code repositories must be treated as compromised,” emphasized Eric Fourrier. “Security teams must recognize that secrets should be treated as sensitive data regardless of where they reside.”

Beyond Code: Secrets Sprawl Across the SDLC

Hardcoded secrets are everywhere, but especially in security blind spots like collaboration platforms and containers environments where security controls are typically weaker:

  • Slack: 2.4% of channels within analyzed workspaces contained leaked secrets
  • Jira: 6.1% of tickets exposed credentials, making it the most vulnerable collaboration tool
  • DockerHub: 98% of detected secrets were embedded exclusively in image layers, with over 7,000 valid AWS keys currently exposed

The Non-Human Identity Crisis

Non-human identities (NHIs)—including API keys, service accounts, and automation tokens—now vastly outnumber human identities in most organizations. However, these credentials often lack proper lifecycle management and rotation, creating persistent vulnerabilities.

A security leader at a Fortune 500 company acknowledged this challenge: “We aim to rotate secrets annually, but enforcement is difficult across our environment. Some credentials have remained unchanged for years.”

Secrets Managers: Not a Complete Answer

Even organizations using secrets management solutions remain vulnerable. A study of 2,584 repositories leveraging secrets managers revealed a 5.1% secret leakage rate —far from the near-zero we anticipate. This surpasses the overall GitHub average of 4.6%.

Common issues include:

  • Secrets extracted from secrets managers and hardcoded elsewhere
  • Insecure authentication to secrets managers exposing access credentials
  • Fragmented governance due to secrets sprawl across multiple secrets managers

The Path Forward: Comprehensive Secrets Security

As AI-generated code, automation, and cloud-native development accelerate, the report forecasts that secrets sprawl will only intensify. While GitHub’s Push Protection has reduced some leaks, it leaves significant gaps—particularly with generic secrets, private repositories, and collaboration tools.

“For CISOs and security leaders, the goal isn’t just detection—it’s the remediation of these vulnerabilities before they’re exploited,” said Eric Fourrier. “This requires a comprehensive approach that includes automated discovery, detection, remediation, and stronger secrets governance across all enterprise platforms.”

The report concludes with a strategic framework for organizations to address secrets sprawl through:

  • Deploying monitoring for exposed credentials across all environments
  • Implementing centralized secrets detection and remediation
  • Establishing semi-automated rotation policies for all credentials
  • Creating clear developer guidelines for secure vault usage

To read the full 2025 State of Secrets Sprawl Report, users can visit GitGuardian.com.

Additional resources

GitGuardian – Website

The State of Secrets Sprawl 2025

About GitGuardian

GitGuardian is an end-to-end NHI security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards. With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and NHI Governance. This dual approach enables the detection of compromised secrets across your dev environments while also managing non-human identities and their secrets’ lifecycles. The platform is the world’s most installed GitHub application and supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense. Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

Contact

Media Contact
Holly Hagerman
Connect Marketing
[email protected]
+1(801) 373-7888

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • Global Scam Losses Near Half a Billion, One in Seven Consumers Hit in 2025
  • Google’s $32 Billion Wiz Bet Meets the OT Grid: Hitachi Becomes Its Critical-Infrastructure Channel
  • Cybersecurity Stocks Fall Friday as Nasdaq’s 4.2% Tech Rout Sweeps Up CrowdStrike and Palo Alto
  • IdentityTheft.org Sells for $30,000 on Sedo
  • Infosecurity Europe 2026, June 2–4, London
  • Ocean Launches From Stealth With $28 Million to Reinvent Email Security Using AI Agents
  • Salt Typhoon, Volt Typhoon, Flax Typhoon: China’s 2024 Campaign Against U.S. Infrastructure
  • Foreign Criminal Cyberattacks Against the United States: Ransomware, Botnets, and Financial Fraud
  • Iran’s Cyber Operations: Infrastructure Attacks, Election Interference, and IRGC Proxies
  • North Korea’s Cyber Program: From Sony to Blockchain Theft

Media Partners

  • Defense Market
  • Technologies.org
  • Technology Conferences
Teledyne FLIR Defense Selected by U.S. Army for LASSO Loitering Munition Program
Heaviside Industries Raises $28M to Push Autonomous Warfare Into Its Next Phase
Israel Approves F-35 and F-15IA Squadron Purchases Worth Tens of Billions
DEFSEC Pushes Battlefield Awareness Forward with BLISS Deployment to Yuma
Farnborough International Airshow 2026, July 20–24, Farnborough, England
6K Energy and CRG Defense Form Seven-Year Pact to Build U.S. Defense Battery Supply Chain
Boeing MQ-25A Stingray First Operational Flight Advances U.S. Navy Carrier Aviation
L3Harris Secures $1 Billion Pentagon-Style Backing Ahead of Missile Solutions IPO
DFEN Unwinds the War Premium
The Industrial Gap Behind Europe’s Rearmament Numbers
The Semiconductor Rotation Myth: There Is No Rotation Out of Semi Stocks, Only Profit-Taking
The AI Selloff Repriced Valuation, Not Demand
Apple’s Next-Generation Apple Intelligence Is Built on Google’s Gemini Models
Itera Emerges From Stealth With Fluid Circuit Board That Rewires in Under a Minute
Quantum Computing Stocks Are Down. They Are Not at the Bottom.
The Humanoid Trap: Form Factor as Distraction in Industrial Robotics
Hark Raises $700M Series A at $6B: The Vertical Integration Bet on Personal AI
Apple Brings Apple Intelligence to Accessibility, Adds Wheelchair Eye Control for Vision Pro
RADAR Raises $170M to Bring Real-Time Inventory Intelligence to Physical Retail
Anthropic’s Stainless Acquisition Is an Infrastructure Seizure Disguised as a Developer Tools Deal
Cloudflare Connect San Francisco, October 19–22, Moscone West
WWDC 2026 Keynote, June 8, 2026, Apple Park, Cupertino
Baird 2026 Global Consumer, Technology & Services Conference, June 2–4, New York
D.A. Davidson Technology Conference, June 11, 2026, Nashville
Bank of America Global Technology Conference, June 4, 2026, San Francisco
William Blair Growth Stock Conference, June 3, 2026, Chicago
TD Cowen Technology, Media & Telecom Conference, May 27, 2026, New York
J.P. Morgan Global Technology, Media and Communications Conference, May 18–20, 2026, Boston
Technology Investor Conference Circuit, May–June 2026
Automate 2026 Sets Its Agenda Around AI’s Role in Industrial Transformation, June 22–25, 2026, McCormick Place in Chicago

Media Partners

  • Market Analysis
  • Market Research Media
  • Analysis.org
SpaceX IPO (SPCX): A $1.75 Trillion Valuation Built on Selling 4% of the Company to People Who Watch Rocket Launches
What a Trillion-Dollar Cloudflare Actually Requires
The Repricing and the Drain: How SpaceX, OpenAI, and Anthropic Rewire the Index
Quantum Computing Equities: Market Segment Memo
Quantum Computing Stocks Face Violent Selloff the Moment Markets Reopen Tuesday
The $2.6 Trillion Signal: What Gartner’s AI Spending Forecast Actually Tells You
The Productivity Is Already Here. The Bubble Narrative Is Not.
The Collingridge Dilemma
Why Memory Prices Won’t Come Down
The Bill Comes Due
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Mamdani Strangling New York
The Rise of Faceless Creators: Picsart Launches Persona and Storyline for AI Character-Driven Content
Oracle’s $95 Billion Capex Guide Meets a 6.5% PPI: Today’s Session Is the Test for Nvidia, AMD, and the AI Chip Trade
PPI May 2026: Producer Prices Surge 1.1% as Iran War Energy Shock Hits the Pipeline, Goods Inflation Sets a Record
June 22 Is the Date That Changes Everything for MRVL Shareholders
SpaceX (SPCX) IPO: Why Facebook’s 2012 Debut Is the Warning Label on the Largest IPO in History
SK Hynix Eyes August US Listing: A $14 Billion ADR Raise Lands in the Middle of the AI Liquidity Pipeline
Supermicro’s $7B Equity Raise: A $39B Order Book the Balance Sheet Can’t Carry
CoreWeave Insiders Cash Out $2.3B: The Magnetar Exit Matters More Than the Founders
After the 4.18% Rout: Why Next Week’s CPI Matters More Than the Selloff, and What the SpaceX IPO Does to the Recovery
The Nasdaq’s 4.18% Collapse: Worst Day Since the Tariff Shock, and What History Says Comes Next
Broadcom’s AI Revenue Grew 143% and the Stock Fell 12% — The Selloff Has No Basis

Copyright © 2026 CybersecurityMarket.com

Media Partners: Technologies · Market Analysis · Market Research · Photography · API Coding · App Coding · Blockchaining · Referently