Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Cybersecurity research team
Word Count
2,901
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Credential harvesting is a significant cybersecurity threat involving the large-scale collection of valid credentials, such as usernames, passwords, API keys, and tokens, which attackers use or sell on the dark web. This is achieved through various techniques, including phishing and malware, with developer machines being particularly vulnerable due to the presence of credentials in plaintext, such as cloud keys and SSH keys, which can be easily accessed by infostealers without user deception. The practice is prevalent, with statistics indicating its role in many data breaches. Defending against credential harvesting requires a dual approach: hardening systems against phishing and minimizing the number of accessible credentials on endpoints. This includes using phishing-resistant multi-factor authentication, regularly rotating credentials, and deploying honeytokens to detect unauthorized access attempts. These strategies complement existing security controls, aiming to reduce the availability of harvestable credentials and promptly alert organizations to potential breaches.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 18 584 99 52 -76%
AI Coding Assistant 2 276 77 47 -83%
Real-time 2 1,106 270 109 -81%
MCP 1 1,562 186 99 -80%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.