github.blog GitHub Enhances Push Protection with AI to Prevent Credential Leaks
Article Content
- •GitHub's AI detector aims to prevent credential leaks during code pushes.
- •The new classifier can identify unstructured secrets in under two milliseconds.
- •Expanded push protection will be available for Enterprise Cloud and Team plans later in October.
GitHub has introduced an AI-based detector, developed with Microsoft Applied Sciences, to prevent developers from inadvertently uploading passwords and other credentials to code repositories. This ModernBERT-based classifier enhances GitHub's existing push protection by identifying unstructured secrets in code, which traditional checks may miss. GitHub reports that a new secret appears in publicly visible code every two seconds, with the number of public code pushes screened increasing by 2.84 times from Q2 2024 to Q2 2026. The new classifier can evaluate potential secrets in under two milliseconds and is expected to more than double the number of secrets prevented from entering repository history. The expanded push protection feature is currently in private preview and will be available later in October 2026 for organizations using GitHub Secret Protection on Enterprise Cloud and GitHub Team plans. GitHub aims to reduce the average manual revocation time of exposed credentials, which currently averages around 40 days.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
How does the AI detector work?
When will the new feature be available?
What is the average time to revoke exposed credentials?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…