By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub | HackerNoon
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub | HackerNoon
Computing

GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub | HackerNoon

News Room
Last updated: 2026/03/17 at 3:09 PM
News Room Published 17 March 2026
Share
GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub | HackerNoon
SHARE

New York, NY, March 17th, 2026/CyberNewswire/–In 2025, Developer Commits Using Claude Code Show 3.2% Secret Leak Rate vs. 1.5% Baseline. The Human Factor Remains Critical

GitGuardian, the security leader behind GitHub’s most installed application, today released the 5th edition of its “State of Secrets Sprawl” report, documenting how mainstream AI adoption in 2025 reshaped software delivery and accelerated the exposure of non-human identities (NHIs) and their secrets across public and internal systems.

While the software ecosystem is growing quickly, leaked secrets are growing faster, and remediation is not keeping up.

The year software changed forever

In 2025, AI adoption permanently changed software engineering:

  • +43% YoY increase in public commits, growing at least 2× faster than before
  • Since 2021, secrets have been growing roughly 1.6× faster than the active developer population
  • Secret leak rates in AI-assisted code were, on average across the year, roughly double the GitHub-wide baseline.

Together, these forces drove a +34% YoY increase in newly leaked secrets on GitHub, reaching ~29 million secrets detected overall, marking the largest single-year jump ever recorded.

Nine takeaways for CISOs securing Non‑Human Identities (NHI)

Exposed credentials remain a major, repeatable path to compromise. In 2025, AI assistance increased the speed of software creation and multiplied the number of tokens, keys, and service identities embedded across modern stacks, without equivalent improvements in governance.

AI assistants are amplifying risk in new categories of credentials

1. Claude Code-assisted commits leaked secrets at ~3.2%, 2× the baseline. AI-assisted coding has democratized software development, enabling developers without formal training to build applications quickly. However, this accessibility comes with a security gap: less experienced developers may lack security awareness and can ignore AI warnings or explicitly prompt tools to include sensitive information. These leaked secrets may ultimately reflect human mistakes, not just AI failures.

2. AI service credentials leaks are accelerating fastest: leaks tied to AI services increased +81% YoY (to 1,275,105), and are more likely to slip through protections built primarily for conventional developer workflows.

3. MCP configuration risk is emerging: MCP server documentation often recommends placing credentials directly in configuration files rather than using safer client authentication patterns. This contributed to 24,008 unique secrets exposed in the studied MCP configuration files.

AI expands the attack surface overnight

4. Internal repositories remain the biggest exposure reservoir. They are ~6× more likely than public ones to contain hardcoded secrets.

5. Secrets sprawl extends beyond code: ~28% of incidents originate from leaks in collaboration and productivity tools (not just repositories), where credentials can be exposed to broader audiences, automations, and AI agents.

6. Developer machines are becoming part of the credential perimeter. As AI agents gain deeper local access (editors, terminals, files, credentials stores), prompt injection and supply-chain style attacks (Shai-Hulud, for example) can turn local secrets into organizational risk.

“AI agents need local credentials to connect across systems, turning developer laptops into a massive attack surface. We built our local scanning and identities inventory tool to protect them. Security teams need to map out exactly which machines hold which secrets, surfacing critical weaknesses like overprivileged access and exposed production keys.” says Eric Fourrier, GitGuardian’s CEO

The industry is facing a growing debt, and needs NHI governance, not just detection

7. Long-lived secrets still dominate: ~60% of policy violations are credentials that persist over time, highlighting the slow transition toward ephemeral, least-privilege access.

8. Prioritization is harder than it looks: ~46% of critical secrets have no vendor-provided validation mechanism, requiring contextual signals (location, usage, downstream consumers, and secrets managers) to assess real-world exploitability.

9. Remediation is failing at scale: 64% of valid secrets from 2022 are still not revoked in 2026, most often because security teams lack the governance needed to achieve a viable, repeatable remediation path for any leaked secret.

GitGuardian believes the next phase of security programs must treat non-human identities as first-class assets: with dedicated governance, context, and remediation automation across code and non-code surfaces.

The full report is available here

About GitGuardian

GitGuardian is an end-to-end NHI Security platform that empowers software-driven organizations to secure their Non-Human Identities (NHIs) and comply with industry standards. With attackers increasingly targeting NHIs, such as service accounts and applications, GitGuardian integrates Secrets Security and NHI Governance. This dual approach enables the detection of compromised secrets across your dev environments while also managing non-human identities and their secrets’ lifecycles. The platform is the world’s most installed GitHub application and supports over 550+ types of secrets, offers public monitoring for leaked data, and deploys honeytokens for added defense. Trusted by over 600,000 developers, GitGuardian is the choice of leading organizations like Snowflake, ING, BASF, and Bouygues Telecom for robust secrets protection.

For more information, users can visit www.gitguardian.com

Contact

PR Partner

Holly Hagerman

Connect Marketing

[email protected]

:::tip

This story was published as a press release by Chainwire under HackerNoon’s Business Blogging Program

:::

Disclaimer:

This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are speculative, complex, and involve high risks. This can mean high prices volatility and potential loss of your initial investment. You should consider your financial situation, investment purposes, and consult with a financial advisor before making any investment decisions. The HackerNoon editorial team has only verified the story for grammatical accuracy and does not endorse or guarantee the accuracy, reliability, or completeness of the information stated in this article. #DYOR

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Teen Girls Sue xAI, Alleging 'Devastating' Harm From Grok AI Child Sexual Abuse Images Teen Girls Sue xAI, Alleging 'Devastating' Harm From Grok AI Child Sexual Abuse Images
Next Article QCon London 2026: Reliable Retrieval for Production AI Systems QCon London 2026: Reliable Retrieval for Production AI Systems
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to Use Facebook Groups to Grow Your Business in 2026
How to Use Facebook Groups to Grow Your Business in 2026
Computing
5 Small business opportunities entrepreneurs should target in 2026
5 Small business opportunities entrepreneurs should target in 2026
News
QCon London 2026: Managing Asynchronous APIs at Scale
QCon London 2026: Managing Asynchronous APIs at Scale
News
Several Sonos audio products got their first 2026 discounts
Several Sonos audio products got their first 2026 discounts
News

You Might also Like

How to Use Facebook Groups to Grow Your Business in 2026
Computing

How to Use Facebook Groups to Grow Your Business in 2026

28 Min Read
ChangeNOW Launches Private Send to Break Blockchain Address Tracking | HackerNoon
Computing

ChangeNOW Launches Private Send to Break Blockchain Address Tracking | HackerNoon

4 Min Read
Tech Moves: Ex-Microsoft leader takes nonprofit CEO role; Google vet joins LinkedIn; Amazon leaders depart
Computing

Tech Moves: Ex-Microsoft leader takes nonprofit CEO role; Google vet joins LinkedIn; Amazon leaders depart

10 Min Read
AMD MLIR-AIE Releases New AIECC C++ Compiler To Help Bring New Workloads To Ryzen AI NPUs
Computing

AMD MLIR-AIE Releases New AIECC C++ Compiler To Help Bring New Workloads To Ryzen AI NPUs

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?