Tag

#secrets management

6 stories taggedsecrets management.

Full-frame close-up, 16:9, of a small circuit board with a USB stick partially inserted, warm amber and cool blue lighting, shallow depth of field, faint solder
Vulnerabilities

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys

Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Identity & Access

Leaked n8n Tokens Left 321 Live Automation Servers Open to Anyone With a GitHub Search

GitGuardian found thousands of API keys for the popular workflow tool spilled into public code repositories, handing attackers a straight path to connected apps and stored secrets.

4 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Cloud Security

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts

The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Identity & Access

AI Agents Need Passports, Not Passwords

As companies hand more decisions to autonomous AI agents, the old rules about who gets access to what are breaking down. Here is what needs to change, and why it matters to everyone.

3 min read
Identity & Access

SailPoint to Buy Entro Security for a Reported $200 Million

The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

2 min read
Cloud Security

CISA Contractor Spent Six Months Treating GitHub as a Personal Dropbox

A Nightwing employee's public 'Private-CISA' repo leaked AWS GovCloud admin keys, plaintext passwords and the agency's internal build pipeline — with secret-scanning deliberately switched off.

2 min read
© 2026 Threat Vectr