www.gitguardian.com AI-Driven Credential Exposure Accelerates Security Risks
Article Content
- •28.65 million new hardcoded secrets were found in GitHub in 2025, a 34% increase.
- •AI-assisted commits leak secrets at twice the baseline rate, raising security concerns.
- •54% of active GitHub developers made their first commit in 2025, increasing exposure risks.
In 2025, GitGuardian reported a staggering 28.65 million new hardcoded secrets in public GitHub commits, a 34% increase from the previous year. AI-assisted commits contributed to credential leaks at twice the baseline rate, while secrets related to AI services surged by 81%. The rise in developer activity, with 54% of active GitHub developers making their first commit in 2025, has exacerbated the issue, leading to compromised machines holding multiple secrets. Security teams are urged to establish reliable reporting channels for external parties to disclose exposed credentials. The current landscape highlights the urgent need for improved governance around credential management as AI tools proliferate. Security experts recommend developing a clear response process for handling reported exposures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CISA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the scale of credential exposure?
How does AI contribute to these leaks?
What should organizations do to mitigate risks?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…