惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
C
Check Point Blog
腾讯CDC
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
Recent Announcements
Recent Announcements
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
J
Java Code Geeks
博客园_首页
Jina AI
Jina AI
美团技术团队
H
Help Net Security
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
Y
Y Combinator Blog
S
SegmentFault 最新的问题

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
How security teams are getting credential visibility into...
Help Net Security · 2026-06-18 · via Help Net Security

As we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub repositories in six hours. TrapDoor spread across npm, PyPI, and Crates.io simultaneously, planting persistence inside AI coding assistant config files. Miasma compromised 32 official Red Hat packages by abusing GitHub’s trusted publishing.

Each campaign shared the same objective: reach developer machines and harvest the credentials sitting on them. Developer workstations have become a high-value target precisely because they concentrate credentials that no perimeter control covers, shell histories, `.env` files, local caches, cloud CLI configs, and now AI agent directories.

Today, GitGuardian is addressing that gap directly with Developer Endpoint Protection: the ability to find every credential on every developer machine, built into ggshield, the CLI already deployed across the GitGuardian customer base.

What it does

Scans the full endpoint, including AI tooling. The scanning engine processes 500,000 files in under three minutes and completes subsequent scans in seconds using intelligent caching. All scanning is local. Credentials never leave the machine in clear text. Beyond traditional file paths, it covers the locations AI coding agents now write to: prompt histories, tool output logs, agent config files, and inventories of which AI tools and MCP servers are running on each machine, surfacing unauthorized or potentially malicious MCPs before they can exfiltrate data.

Detects live attacks with honeytokens. Honeytokens placed on developer machines fire the moment an infostealer validates one of those credentials. Instead of discovering a breach weeks later in a log review, security teams get attribution-rich alerts in real time, before the credential is used.

Feeds into the broader platform. Endpoint findings surface directly in the GitGuardian dashboard alongside vault, repository, and cloud data, connecting endpoint exposure to the NHI governance and secrets security workflows teams already use. When an incident lands, teams can answer immediately: what was on this machine, what services does it reach, and what needs to be revoked first.

Designed for enterprise deployment

Developer Endpoint Protection is built for organizations that need more than a proof of concept. It supports MDM-based rollout via Intune and Jamf, structured output forwarding to SIEM, API-based data retrieval, configurable exclusions with CPU and memory limiting, and cross-platform coverage across Windows, Linux, and macOS. Because it extends ggshield rather than introducing a new tool, teams already using GitGuardian for pre-commit hooks and CI/CD scanning can deploy without adding another agent or workflow.

Why now

Supply chain attackers have already updated their model. Machine identities and developer machine credentials are a primary objective, not an afterthought. Megalodon, TrapDoor, Miasma, and the campaigns that preceded them, including Shai-Hulud and NX, all demonstrate the same calculus: compromising one developer machine or CI workflow is often enough to reach production credentials, repository access, and cloud environments in a single step.

AppSec programs that stop their visibility at repositories and CI pipelines are working with an incomplete map of where credentials actually live. Developer Endpoint Protection is how GitGuardian extends that map to the machines themselves.

Developer endpoints are the most under-monitored surface in secrets security. The organizations that know what credentials are on their fleet recover faster when the next campaign lands. The ones that don’t find out during the breach.

Ready to see what’s on your fleet? Start your pilot