By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Explosive Growth of Non-Human Identities Creating Massive Security Blind Spots
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Explosive Growth of Non-Human Identities Creating Massive Security Blind Spots
Tech News

Explosive Growth of Non-Human Identities Creating Massive Security Blind Spots

By Viral Trending Content 7 Min Read
Share
SHARE

Apr 09, 2025The Hacker NewsSecrets Management / DevOps

Contents
The Non-Human Identity CrisisPrivate Repositories: A False Sense of SecurityAI Tools Worsening the ProblemDocker Hub: 100,000+ Valid Secrets ExposedBeyond Source Code: Secrets in Collaboration ToolsThe Permissions ProblemBreaking the Cycle of Secrets Sprawl
Non-Human Identities

GitGuardian’s State of Secrets Sprawl report for 2025 reveals the alarming scale of secrets exposure in modern software environments. Driving this is the rapid growth of non-human identities (NHIs), which have been outnumbering human users for years. We need to get ahead of it and prepare security measures and governance for these machine identities as they continue to be deployed, creating an unprecedented level of security risk.

This report reveals an astounding 23.77 million new secrets were leaked on GitHub in 2024 alone. This is a 25% surge from the previous year. This dramatic increase highlights how the proliferation of non-human identities (NHIs), such as service accounts, microservices, and AI agents, are rapidly expanding the attack surface for threat actors.

The Non-Human Identity Crisis

NHI secrets, including API keys, service accounts, and Kubernetes workers, now outnumber human identities by at least 45-to-1 in DevOps environments. These machine-based credentials are essential for modern infrastructure but create significant security challenges when mismanaged.

Most concerning is the persistence of exposed credentials. GitGuardian’s analysis found that 70% of secrets first detected in public repositories back in 2022 remain active today, indicating a systemic failure in credential rotation and management practices.

Private Repositories: A False Sense of Security

Organizations may believe their code is secure in private repositories, but the data tells a different story. Private repositories are approximately 8 times more likely to contain secrets than public ones. This suggests that many teams rely on “security through obscurity” rather than implementing proper secrets management.

The report found significant differences in the types of secrets leaked in private versus public repositories:

  • Generic secrets represent 74.4% of all leaks in private repositories versus 58% in public ones
  • Generic passwords account for 24% of all generic secrets in private repositories compared to only 9% in public repositories
  • Enterprise credentials like AWS IAM keys appear in 8% of private repositories but only 1.5% of public ones

This pattern suggests that developers are more cautious with public code but often cut corners in environments they believe are protected.

AI Tools Worsening the Problem

GitHub Copilot and other AI coding assistants might boost productivity, but they’re also increasing security risks. Repositories with Copilot enabled were found to have a 40% higher incidence rate of secret leaks compared to repositories without AI assistance.

This troubling statistic suggests that AI-powered development, while accelerating code production, may be encouraging developers to prioritize speed over security, embedding credentials in ways that traditional development practices might avoid.

Docker Hub: 100,000+ Valid Secrets Exposed

In an unprecedented analysis of 15 million public Docker images from Docker Hub, GitGuardian discovered more than 100,000 valid secrets, including AWS keys, GCP keys, and GitHub tokens belonging to Fortune 500 companies.

The research found that 97% of these valid secrets were discovered exclusively in image layers, with most appearing in layers smaller than 15MB. ENV instructions alone accounted for 65% of all leaks, highlighting a significant blind spot in container security.

Beyond Source Code: Secrets in Collaboration Tools

Secret leaks aren’t limited to code repositories. The report found that collaboration platforms like Slack, Jira, and Confluence have become significant vectors for credential exposure.

Alarmingly, secrets found in these platforms tend to be more critical than those in source code repositories, with 38% of incidents classified as highly critical or urgent compared to 31% in source code management systems. This happens partly because these platforms lack the security controls present in modern source code management tools.

Alarmingly, only 7% of secrets found in collaboration tools are also found in the code base, making this area of secrets sprawl a unique challenge that most secret scanning tools can not mitigate. It is also exasperated by the fact that the users of these systems cross all department boundaries, meaning everyone is potentially leaking credentials into these platforms.

The Permissions Problem

Further exacerbating the risk, GitGuardian found that leaked credentials frequently have excessive permissions:

  • 99% of GitLab API keys had either full access (58%) or read-only access (41%)
  • 96% of GitHub tokens had write access, with 95% offering full repository access

These broad permissions significantly amplify the potential impact of leaked credentials, enabling attackers to move laterally and escalate privileges more easily.

Breaking the Cycle of Secrets Sprawl

While organizations increasingly adopt secret management solutions, the report emphasizes these tools alone aren’t enough. GitGuardian found that even repositories using secrets managers had a 5.1% incidence rate of leaked secrets in 2024.

The problem requires a comprehensive approach that addresses the entire secrets lifecycle, combining automated detection with swift remediation processes and integrating security throughout the development workflow.

As our report concludes, “The 2025 State of Secrets Sprawl Report offers a stark warning: as non-human identities multiply, so do their associated secrets—and security risks. Reactive and fragmented approaches to secrets management simply aren’t enough in a world of automated deployments, AI-generated code, and rapid application delivery.”

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Top 3 leadership myths debunked

Adds Device Fingerprinting, PNG Steganography Payloads

Your Delivery Robot Is Here

Samsung Galaxy Tab S11 Review: It’s Time For Something New

How the World’s Largest 3D Object Library By Microsoft & NVIDIA

TAGGED: API Security, Cloud security, Container Security, Cyber Security, Cybersecurity, data breach, DevOps, Identity Security, Internet, Secrets Management, software development
Share This Article
Facebook Twitter Copy Link
Previous Article Bitcoin jumps over 8% to $81,700 after Trump announces 90-day tariff pause; Ethereum, XRP gain over 12%
Next Article Murderbot's Trailer Has Alexander Skarsgård As A Killing Machine With Deadpan Humor
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The best guns in the Black Ops 7 beta in early access
Gaming News
6-story office building to be converted into housing in Denver’s Capitol Hill
Business
Could Trump’s $2,000 tariff rebates for Americans stimulate an altcoin surge?
Crypto
Hegseth announces latest strike on boat near Venezuela he says was trafficking drugs
World News
Top 3 leadership myths debunked
Tech News
Bitcoin Holders Locking In Gains As Profit-Taking Surges Amid Market Recovery, Rally To Extend?
Crypto
Adds Device Fingerprinting, PNG Steganography Payloads
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The best guns in the Black Ops 7 beta in early access

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The best guns in the Black Ops 7 beta in early access
October 3, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?