How Cybercriminal Organizations Weaponize Exposed Secrets
Blog post from GitGuardian
Highly organized criminal groups are executing systematic cloud attacks centered on exploiting hardcoded credentials and permissive IAM configurations, as anticipated by GitGuardian. The recent Red Hat breach, claimed by the Crimson Collective, exposed vast amounts of sensitive data from numerous organizations, escalating into coordinated extortion efforts with the ShinyHunters and Scattered Lapsus$ Hunters. These groups focus on AWS credentials, using open-source tools to identify and exploit secrets at scale, following a structured attack strategy involving persistence, discovery, collection, and exfiltration of data. The breaches underscore the critical security risk posed by secrets sprawl, particularly within consulting firms that often contain significantly more secrets than public repositories. This issue was highlighted by the Scattered Lapsus$ Hunters attack on Salesloft, where initial access led to further discovery and exfiltration of sensitive credentials. These developments emphasize the need for improved control and understanding of Non-Human Identity entitlements and a fundamental shift in security practices to manage the increasing proliferation of secrets across modern infrastructures.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 13 | 1,168 | 199 | 91 | +15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.