Threat Intelligence

Credentials Are Multiplying Faster Than Security Teams Can Track Them

The Hacker News · 5 Oct 2026
Key Takeaway Start by finding out which passwords, keys and tokens your business has, where they are stored and what they can access, because you cannot protect credentials you cannot see.

Every modern business relies on credentials such as passwords, keys and tokens to let people, systems and now AI tools connect to data and services. According to the article, the pace of software production is outstripping the assumptions behind many current security controls. GitHub's COO Kyle Daigle reportedly said the platform went from roughly 1 billion commits in all of 2025 to 2.9 billion in August 2026, an annualised pace of over 14 billion. GitHub's engineering team also said it has moved from planning for 10x scale to designing for 30x as agent-driven development grows.

More code means more applications, integrations, automations and agents, and each one needs to authenticate to something else. The article notes that GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits in 2025, up 34% year over year. Leaked credentials linked to AI services rose 81%.

The piece comes from GitGuardian, which describes a three-stage approach to securing this credential layer: Detect, Remediate and Prevent. It argues detection must come first, because every later step depends on knowing which credentials exist, where they have spread and what access they provide. This is the opening of a three-part series, so it covers only the first stage of that argument.

credentials secrets GitHub AI security
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.