February 2021 Summaries
4 posts from GitGuardian
Filter
Month:
Year:
Post Summaries
Back to Blog
GitGuardian CEO Jeremy Thomas discussed the company's recent accolade as the FIC start-up of the year on national French television, highlighting their role in enhancing cybersecurity within software development. GitGuardian focuses on detecting "secrets" within source code—sensitive information like passwords that are programmatically used—which, if exposed, can lead to significant vulnerabilities. As the software development landscape evolves with increased reliance on external components, GitGuardian aims to integrate closely with developers and security teams to address vulnerabilities early. Despite its French origins, the company has prioritized expansion in the U.S., reflecting its strategy to maintain a global presence and capitalize on the responsiveness of American clients. Thomas also acknowledged the dynamic nature of the application security industry, emphasizing collaboration with complementary security solutions and expressing optimism about future growth and recruitment.
Feb 24, 2021
1,498 words in the original blog post.
GitGuardian was honored as the 2021 winner of the FIC Cybersecurity Start-up of the Year Award, a recognition given by the International Cybersecurity Forum to foster innovation in the cybersecurity sector. Out of 52 nominees, GitGuardian stood out among 11 finalists, evaluated by a jury led by Zeina Zakhour from ATOS, for its innovative secret detection solution which addresses significant market challenges. The award acknowledges GitGuardian’s maturity and economic viability, positioning it alongside previous winners like Alsid and Sqreen. The FIC event, a key cybersecurity forum in Europe, combines a trade show and summit, and this year it hosted 40 startups, highlighting the importance of collaboration between global players and startups in advancing digital security. GitGuardian's CEO, Jeremy Thomas, expressed pride in the award, noting plans to expand the company’s international presence and revenue, particularly in Europe, as the region matures in software development security.
Feb 12, 2021
665 words in the original blog post.
Sakura Samurai, an ethical hacking group, successfully breached United Nations (UN) systems by exploiting publicly exposed credentials and vulnerabilities, gaining access to sensitive employee data. The attack began with the discovery of the UN Vulnerability Disclosure Program, leading the hackers to use URL fuzzing to identify an exposed .git repository on ilo.org, where they extracted hardcoded credentials to access internal systems. The hackers then infiltrated a password-protected GitHub repository of the United Nations Environment Programme, uncovering personal identifiable information (PII) of UN employees. Although the attack was notable for its low-tech approach and minimal costs, it was executed with ethical intentions, as the hackers reported the vulnerabilities to the UN rather than exploiting them further. The incident underscores the importance of robust security measures, particularly in managing credentials and monitoring for vulnerabilities, to prevent potentially devastating data breaches by malicious actors.
Feb 10, 2021
884 words in the original blog post.
Talend, a leader in data integration and integrity solutions, faced significant challenges with infrastructure credentials and secrets leaking through GitHub, an issue identified by CISO Anne Hardy upon her arrival in 2020. Despite initial attempts to address the problem with an in-house tool, Talend recognized its limitations and sought a more effective market solution, eventually adopting GitGuardian's GitHub public monitoring solution. This decision enabled rapid remediation of past incidents and comprehensive monitoring of both company and personal developer repositories, revealing that the majority of leaks originated from personal code repositories. After extensive training of their 400 developers and implementing a new procedure for handling leaks, Talend successfully cleaned up past issues within three months. GitGuardian now provides real-time alerts, allowing Talend to continuously monitor all code commits and address credential leaks swiftly. The company plans to expand the use of GitGuardian to security champions within its team to ensure ongoing adherence to best practices.
Feb 06, 2021
617 words in the original blog post.