Socket says more than 500 GitHub accounts added a malicious file across tens of thousands of repositories.
It searches project history too, incl…

Socket says more than 500 GitHub accounts added a malicious file across tens of thousands of repositories.
It searches project history too, incl…
GitHub’s new AI tool checks code changes for hidden passwords before submission.
The company says it stops about 30% of the credentials it scans before t…
GitHub’s ModernBERT flags hidden passwords pre-push—real-time secret protection goes live in October. #Security #GitHub #AI #SecretScanning #DevSecOps #ModernBERT https://thedailytechfeed.com/githubs-new-ai-flags-hidden-passwords-before-code-push/
Push protection stops the secret before it exists in history
Secret scanning alerts after the fact; push protection rejects the push outright.
#GH100 #GitHub #DevSecOps #SecretScanning
Full GH-100 explanation, free: https://navyduck.com/github/gh-100/q045-what-is-githubs-push-protection-feature
GitGuardian discovered 474 leaked GitHub App private keys still active. Learn how exposed GitHub App private keys threaten organizations like the CDC.
#GitHubSecurity #SecretScanning #DataExposure #GitGuardian #CyberSecurity
AWS cuts credential leaks to seconds: exposed IAM keys now auto-quarantined after GitHub leak. #AWS #CloudSecurity #IAM #SecretScanning #GitHub #BreachResponse https://thedailytechfeed.com/aws-can-quarantine-leaked-iam-keys-in-10-seconds-after-github-exposure/