• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2026-2027
  • Sponsored Post
  • Market Reports
  • About
    • GDPR
  • Contact

GitGuardian Report: 70% of Leaked Secrets Remain Active for Two Years, Urging Immediate Remediation

March 11, 2025 By CyberNewswire Leave a Comment

Boston, USA, March 11th, 2025, CyberNewsWire

GitGuardian, the security leader behind GitHub’s most installed application, today released its comprehensive “2025 State of Secrets Sprawl Report,” revealing a widespread and persistent security crisis that threatens organizations of all sizes. The report exposes a 25% increase in leaked secrets year-over-year, with 23.8 million new credentials detected on public GitHub in 2024 alone.

Most concerning for enterprise security leaders: 70% of secrets leaked in 2022 remain active today, creating an expanding attack surface that grows more dangerous with each passing day.

“The explosion of leaked secrets represents one of the most significant yet underestimated threats in cybersecurity,” said Eric Fourrier, CEO of GitGuardian. “Unlike sophisticated zero-day exploits, attackers don’t need advanced skills to exploit these vulnerabilities—just one exposed credential can provide unrestricted access to critical systems and sensitive data.”

Eric Fourrier points to the 2024 U.S. Treasury Department breach as a warning: “A single leaked API key from BeyondTrust allowed attackers to infiltrate government systems. This wasn’t a sophisticated attack—it was a simple case of an exposed credential that bypassed millions in security investments.”

Key Findings for Security Leaders

The report identifies several critical trends that demand immediate attention:

The Blind Spot: Generic Secrets

Despite GitHub’s Push Protection helping developers detect known secret patterns, generic secrets—including hardcoded passwords, database credentials, and custom authentication tokens—now represent more than half of all detected leaks. These credentials lack standardized patterns, making them nearly impossible to detect with conventional tools.

Private Repositories: A False Sense of Security

The analysis reveals a startling truth: a full 35% of all private repositories scanned contained at least one plaintext secret, shattering the common assumption that private repositories are secure:

  • AWS IAM keys appeared in plaintext in 8.17% of private repositories—over 5× more frequently than in public ones (1.45%)
  • Generic passwords appeared nearly 3× more often in private repositories (24.1%) compared to public ones (8.94%)
  • MongoDB credentials were the most frequently leaked secret type in public repositories (18.84%)

“Leaked secrets in private code repositories must be treated as compromised,” emphasized Eric Fourrier. “Security teams must recognize that secrets should be treated as sensitive data regardless of where they reside.”

Beyond Code: Secrets Sprawl Across the SDLC

Hardcoded secrets are everywhere, but especially in security blind spots like collaboration platforms and containers environments where security controls are typically weaker:

  • Slack: 2.4% of channels within analyzed workspaces contained leaked secrets
  • Jira: 6.1% of tickets exposed credentials, making it the most vulnerable collaboration tool
  • DockerHub: 98% of detected secrets were embedded exclusively in image layers, with over 7,000 valid AWS keys currently exposed

The Non-Human Identity Crisis

Non-human identities (NHIs)—including API keys, service accounts, and automation tokens—now vastly outnumber human identities in most organizations. However, these credentials often lack proper lifecycle management and rotation, creating persistent vulnerabilities.

A security leader at a Fortune 500 company acknowledged this challenge: “We aim to rotate secrets annually, but enforcement is difficult across our environment. Some credentials have remained unchanged for years.”

Secrets Managers: Not a Complete Answer

Even organizations using secrets management solutions remain vulnerable. A study of 2,584 repositories leveraging secrets managers revealed a 5.1% secret leakage rate —far from the near-zero we anticipate. This surpasses the overall GitHub average of 4.6%.

Common issues include:

  • Secrets extracted from secrets managers and hardcoded elsewhere
  • Insecure authentication to secrets managers exposing access credentials
  • Fragmented governance due to secrets sprawl across multiple secrets managers

The Path Forward: Comprehensive Secrets Security

As AI-generated code, automation, and cloud-native development accelerate, the report forecasts that secrets sprawl will only intensify. While GitHub’s Push Protection has reduced some leaks, it leaves significant gaps—particularly with generic secrets, private repositories, and collaboration tools.

“For CISOs and security leaders, the goal isn’t just detection—it’s the remediation of these vulnerabilities before they’re exploited,” said Eric Fourrier. “This requires a comprehensive approach that includes automated discovery, detection, remediation, and stronger secrets governance across all enterprise platforms.”

The report concludes with a strategic framework for organizations to address secrets sprawl through:

  • Deploying monitoring for exposed credentials across all environments
  • Implementing centralized secrets detection and remediation
  • Establishing semi-automated rotation policies for all credentials
  • Creating clear developer guidelines for secure vault usage

To read the full 2025 State of Secrets Sprawl Report, users can visit GitGuardian.com.

Additional resources

GitGuardian – Website

The State of Secrets Sprawl 2025

About GitGuardian

GitGuardian is an end-to-end NHI security platform that empowers software-driven organizations to enhance their Non-Human Identity (NHI) security and comply with industry standards. With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and NHI Governance. This dual approach enables the detection of compromised secrets across your dev environments while also managing non-human identities and their secrets’ lifecycles. The platform is the world’s most installed GitHub application and supports over 450+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense. Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

Contact

Media Contact
Holly Hagerman
Connect Marketing
[email protected]
+1(801) 373-7888

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • International Cybersecurity Challenge 2026, May 18–21, Gold Coast, Australia
  • Bitdefender Expands GravityZone With Extended Email Security to Close the Inbox Gap
  • The Security Blind Spot Inside the Arduino-Powered IoT Boom
  • Altum Strategy Group: Cybersecurity in 2026 Is No Longer a Technology Problem
  • Trent AI and the Security Layer the Agentic Stack Has Been Missing
  • Gartner Security & Risk Management Summit, June 1–3, 2026, National Harbor, MD
  • Ashdod Port Has Blocked 134,000 Cyberattacks—and Kept Israel’s Trade Moving
  • Black Hat Asia 2026, April 23–24, Singapore
  • World Backup Day 2026: Why Recovery Has Become the Real Test of Cyber Resilience
  • Cyberhaven Launches Agentic AI Security as Shadow Agents Move Onto the Enterprise Endpoint

Media Partners

  • Defense Market
  • Technologies.org
  • Technology Conferences
ATARS Meets the M-346: Why Leonardo and Red 6 May Be Rewriting the Logic of Fighter Training
Dark Eagle: The U.S. Army’s Long-Range Hypersonic Weapon, Brief Overview
The Army Just Launched a Solicitation for a Heavier ISV — Here’s What We Know
The ISV’s $308 Million Budget Request — and Why Congress Is Pushing Back
From Prototype to Full-Rate Production: The ISV’s Development Timeline
ISV Specs and Deployment: How the Army Gets This Vehicle Into a Fight
Meet the ISV: The Army’s Lightweight Vehicle Built for Speed Over Armor
Affordable Mass: DARPA’s Push for Cheap Missiles Signals a Doctrinal Reset in Modern Warfare
Cheap Wins Wars: America’s Late Turn Toward Cost-Asymmetric Weapons
From Scrap to Supremacy: 6K Additive’s $1.95M Bet on Rebuilding the U.S. Defense Material Base
Booz Allen Backs Ulysses to Scale Autonomous Maritime Robotics
Quantum for Bio Challenge Winners Signal Real Momentum for Quantum Computing in Healthcare
Expo Raises $45 Million to Push Agentic Mobile App Development Into Production Reality
What are the reasons technology companies get acquired?
Resolve AI Raises $40 Million to Build the Missing Layer Between AI Models and Production Reality
Wayve’s $60 Million Extension Matters Because the Intelligence Stays on the Machine
Accenture Bets on Physical AI with General Robotics Investment
NanoTech Materials Raises $29.4 Million to Scale Energy-Saving and Fire-Resistant Coatings
Top 10 Emerging Technologies for 2026
The Machine That Thinks in Two Languages: Quantum Meets Supercomputing in Japan
COMPUTEX 2026, June 2–5, Taipei Nangang Exhibition Center & Taipei World Trade Center
ENGAGE 2026, April 27–28, New York
NAB Show 2026, April 18–22, Las Vegas
VivaTech 2026, June 17–20, Porte de Versailles, Paris
Accelerate 2026, May 21–22, 2026, Salt Palace Convention Center
JSNation 2026, June 11 & June 15, Amsterdam and Remote
ICMC 2026, July 30–31, Long Beach
Elevate 2026, April 22–24, 2026, Atlanta
WWDC 2026, June 8–12, Cupertino & Online
Zip Forward Europe 2026, April 16, 2026, London

Media Partners

  • Market Analysis
  • Market Research Media
  • Analysis.org
Synera’s $40M Series B: What the Press Release Isn’t Saying
Amazon’s Globalstar Acquisition Is a Spectrum War Dressed as a Satellite Deal
The End of Manual Audits: Why AI-Native Accounting Is Not Optional Anymore
Raspberry Pi’s Earnings Beat Signals a Shift From Hobbyist Hardware to Embedded Infrastructure
Betting the Backbone: A Multi-Year Positioning on AMD, Broadcom, and Nvidia
Nvidia’s Groq 3 LPX: The $20B Bet That Could Define the Inference Era
Why Arm’s New AI Chip Changes the Rules of the Game
A Map Without Hormuz: Rewiring Global Oil Flows Through Fragmented Corridors
RoboForce’s $52 Million Raise Signals That Physical AI Is Moving From Demo Stage to Industrial Scale
The Hormuz Crisis: Winners and Losers in the Global Energy Shock
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Mamdani Strangling New York
The Rise of Faceless Creators: Picsart Launches Persona and Storyline for AI Character-Driven Content
Apple TV Arrives on The Roku Channel, Expanding the Streaming Platform Wars
Why Attraction-Grabbing Stations Win at Tech Events
Why Nvidia Let Go of Arm, and Why It Matters Now
When the Market Wants a Story, Not Numbers: Rethinking AMD’s Q4 Selloff
Cloudflare Shares Are Poised for a Jump — Here Is Why the Setup Is Compelling
Nvidia, AMD, and Broadcom Are Rising Again — and the Market Is Telling You Something
OPEC+ in a Blocked Market: Why 200,000 Barrels Don’t Matter
Oil Shock 2026: Hormuz Risk Premium Rewrites the Curve
Why ServiceNow, Salesforce, and Atlassian Fell on the Anthropic Mythos Announcement
Broadcom’s Quiet Power Play: Strong AI Tailwinds, Yet a Stock Caught Between Cycles
Nvidia’s AI Dominance Is Real—So Why Doesn’t the Stock Feel Untouchable?
The Cost of Winning AI: Why Microsoft’s Stock Is Stuck Between Growth and Doubt
Memory Market Reality Check: Micron’s Drop Ripples Across the Sector
The Rise of China’s Hottest New Commodity: AI Tokens

Copyright © 2022 CybersecurityMarket.com

Technologies, Market Analysis & Market Research, Photography