Photo de couverture de GitGuardian
GitGuardian

GitGuardian

Sécurité informatique et des réseaux

Paris, Île-de-France 19 251 abonnés

The end-to-end platform for Secrets and Non-Human Identity Security.

À propos

***** We're hiring: building an outstanding team of developers in Paris right now! Apply! ***** GitGuardian is the end-to-end NHI security leader. GitGuardian helps you take control of your NHI security by discovering all your secrets, prioritizing and remediating leaks at scale, ultimately protecting your non-human identities, and reducing breach exposure. Widely adopted by developer communities, GitGuardian is used by over 600 thousand developers and leading companies, including Snowflake, Orange, Iress, Mirantis, Maven Wave, ING, BASF, and Bouygues Telecom. GitGuardian is the number 1 security app on the GitHub Marketplace. Try it for free today: https://dashboard.gitguardian.com/

Site web
https://www.gitguardian.com
Secteur
Sécurité informatique et des réseaux
Taille de l’entreprise
51-200 employés
Siège social
Paris, Île-de-France
Type
Société civile/Société commerciale/Autres types de sociétés
Fondée en
2017
Domaines
Data Loss Prevention, Cybersecurity, Supply chain security, Application Security, Code Security, Cybersecurity, DevSecOps, endpoint security et NHI security

Produits

Lieux

Employés chez GitGuardian

Nouvelles

  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    Why hack in when you can just log in? 🗝️ Most breaches start with a leaked credential. GitGuardian kills the leak before it happens. MokN catches the login if a stolen one slips through anyway. Test your luck at the one Black Hat booth combo built to stop both. 🎰 Spin the slot machine at GitGuardian Booth #1970 for your first chip 🎣 Grab your second chip at MokN Booth #6316 🎁 Two chips = entry into the raffle, one prize per day, at 5PM Mandalay Bay, August 4-6 Book a slot with GitGuardian: https://lnkd.in/eys5DcyF

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    A compromised developer laptop can expose far more than the device itself. Developer machines accumulate cloud keys, SSH keys, CLI credentials, cached tokens, and secrets stored across local files and tools. After a compromise, EDR and forensics can help reconstruct what happened. Incident responders still need to know which valid credentials were present, what they could access, and which ones must be revoked first. Without that inventory, teams face a costly choice: rotate everything and risk disruption, or rotate too little and leave active credentials exposed. A per-machine credential inventory, built before the incident and enriched with validity, location, history, and ownership, turns that scramble into a prioritized rotation plan. Learn how to assess the credential blast radius of a laptop compromise: https://lnkd.in/e_55NT3p #EndpointSecurity #SecretsSecurity #IncidentResponse

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    An autonomous AI agent breached Hugging Face. During an internal OpenAI evaluation, the models exploited a zero-day to reach the open internet. They then compromised Hugging Face’s dataset-processing pipeline, harvested cloud and cluster credentials, and moved laterally across internal infrastructure. The attacker was new, but the attack path was familiar. Exploits created the foothold. Reusable credentials expanded the blast radius. That distinction is important for security leaders. Agentic attacks introduce new risks like machine-speed operations, long attack chains, and a heavier forensic burden. But the conditions that allowed this incident to reach production are already familiar: credentials exposed on compromised systems, standing access, production environments reachable from untrusted processing workloads, and internal paths that allow stolen credentials to travel. Our latest analysis breaks down what happened, what this incident changes, and five controls organizations can apply now. Read the full article: https://lnkd.in/eJsxAsVz #AgenticAI #SecretsSecurity #Cybersecurity

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    Five minutes. That’s how quickly Dependabot began propagating a poisoned version of Axios. Within the attack window, 895 repositories were affected. Roughly 60% of the bot-opened pull requests GitGuardian analyzed were merged. Fifty were merged by bot users without any human interaction. The tooling teams deploy to stay current became the delivery mechanism. The payload’s real target was not the application. Like every campaign profiled in our new whitepaper, it hunted credentials. The Shai-Hulud 2.0 dataset shows what that harvest looks like. Across 20,649 exfiltration repositories, attackers collected 33,185 unique secrets, 3,760 of them confirmed valid at analysis time. The median compromised machine held more than 10 secrets. By the time responders isolate a machine and begin rotating credentials, the stolen access may already be in use somewhere else. Our new whitepaper traces these campaigns end to end and explains why the organizations best positioned to contain them are the ones that built a complete inventory of their secrets and non-human identities before they needed it. Read it now: https://lnkd.in/esQKigdX #SupplyChainSecurity #SecretsSecurity #NonHumanIdentity

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    🔦 Black Hat USA 2026 Talk Spotlight : "Catch It, Vault It: The Life of a Leaked Credential" Every leaked secret has a life cycle. Most companies never see it, until it's too late. GitGuardian's Ben M. and 1Password's Matt Egan trace one leaked credential from exposure to resolution: what's fueling this year's surge in credential-based attacks, how a secret gets caught and validated, how it's prioritized, and how it ends up permanently vaulted instead of sitting exposed in your codebase. Catch us live to see where detection ends and governance begins, plus a first look at what's next for the GitGuardian x 1Password partnership. 🕚 Aug 5, 11:00–11:15 AM 📍 Booth #4735 Add it to your Black Hat schedule and swing by! #BlackHatUSA #SecretsManagement #DevSecOps

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    Removing an exposed secret from code does not revoke the access it provides. The credential may have no clear owner, teams may not know what depends on it, revocation steps vary by provider, and closing the remediation ticket can create a false sense that the exposure is resolved. Reducing time to revoke requires a clear path from detection to invalidation: • Validate whether the credential still works • Map it to the identity and owner behind it • Build provider-specific revocation runbooks • Separate emergency revocation from coordinated rotation • Automate high-confidence actions where it is safe • Verify the old credential no longer works before closing the incident Our latest article breaks down the operational blockers that keep exposed credentials valid and introduces a maturity model for moving toward automated revocation and verification. Read it here: https://lnkd.in/eTSfVPe8

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    Secrets exposure has grown 152% since 2021. And 64% of the secrets leaked back in 2022 are still valid today. One week from now, we'll be at Black Hat USA talking through exactly why old leaks keep coming back to bite teams, and how the GitGuardian platform closes that gap for good. 📍 Booth #1970 | Aug 4-6 | Mandalay Bay 👉 Book a meeting here: https://lnkd.in/et-ih2fk 7 days to go! ⏳ #BlackHatUSA #AppSec #DevSecOps #SecretsSprawl

    • Aucune description alternative pour cette image
  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    Every laptop is a credential store. How do you inventory it like one? In this webinar replay, C.J. May of Vermeer Corporation joins GitGuardian's Emmanuelle F. to share practical lessons on securing developer environments, improving credential visibility, and bringing endpoint risk into the security program. Watch the replay: https://lnkd.in/eeaBhG5W #SecretsSecurity #EndpointSecurity

  • Voir la Page de l’organisation de GitGuardian

    19 251  abonnés

    In 2003, thieves emptied the vault beneath the Antwerp World Diamond Centre. Ten layers of security. Every one behaved exactly as designed. The door required a combination and a key. The crew filmed a guard entering the combination. The key hung in a utility room steps from the vault. That night, they used both exactly as the guards did every morning. More than $100 million left the building. Your security stack runs on the same basic design. SAST analyzes code. EDR watches endpoints. Vaults govern enrolled secrets. IAM determines who should have access. Each control does its job, but every path converges on the same moment: something presents a credential and a system says yes. When an attacker holds a valid credential, the access can look legitimate. Among ransomware victims with a prior credential leak, half were hit within 95 days. Credentials are the one thing every control depends on and the one thing none of them fully owns. Everyone’s dependency. No one’s job. Our new ebook examines how credentials fall between the boundaries of the security stack and what it takes to own that shared dependency. Read The Secrets Problem: https://lnkd.in/ehXmiPge #SecretsSecurity #IdentitySecurity #Cybersecurity

    • Aucune description alternative pour cette image

Pages similaires

Parcourir les offres d’emploi