Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

How Cybercriminal Organizations Weaponize Exposed Secrets

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Guillaume Valadon, Gaetan Ferry
Word Count
693
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

Highly organized criminal groups are executing systematic cloud attacks centered on exploiting hardcoded credentials and permissive IAM configurations, as anticipated by GitGuardian. The recent Red Hat breach, claimed by the Crimson Collective, exposed vast amounts of sensitive data from numerous organizations, escalating into coordinated extortion efforts with the ShinyHunters and Scattered Lapsus$ Hunters. These groups focus on AWS credentials, using open-source tools to identify and exploit secrets at scale, following a structured attack strategy involving persistence, discovery, collection, and exfiltration of data. The breaches underscore the critical security risk posed by secrets sprawl, particularly within consulting firms that often contain significantly more secrets than public repositories. This issue was highlighted by the Scattered Lapsus$ Hunters attack on Salesloft, where initial access led to further discovery and exfiltration of sensitive credentials. These developments emphasize the need for improved control and understanding of Non-Human Identity entitlements and a fundamental shift in security practices to manage the increasing proliferation of secrets across modern infrastructures.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 13 1,168 199 91 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.