09/10/2026
28.65 million secrets leaked to public GitHub in 2025. A 34% jump, the largest single-year increase GitGuardian has ever recorded. But here's the number that should actually worry you: 64% of secrets confirmed valid in 2022 were still live and exploitable in January 2026.
We spent a decade hardening human passwords. Meanwhile machine credentials multiplied with no MFA, no expiration, and no owner.
Where they leak surprised me. About 28% of incidents originate outside repositories entirely, in Slack messages, Jira tickets, and Confluence pages. Internal repos are 6x more likely than public ones to contain hardcoded secrets, because private feels safe. AI-assisted commits leak at roughly double the baseline rate. And MCP configuration files for AI agents exposed 24,000+ unique secrets in 2025, mostly because quickstart docs showed hardcoded keys and developers copied the pattern.
The program is three verbs.
Eliminate. Managed identities and Entra Workload ID federation let Azure workloads, GitHub Actions, and Kubernetes authenticate with no stored secret at all. No secret, no leak. Make it the default for everything new.
Scope. Every surviving secret gets least privilege, a named owner, an expiration, and a home in Azure Key Vault. A read-only key leaking is an incident. A contributor key leaking is a breach.
Rotate. Long-lived secrets drive 60% of policy violations. A credential that has lived a year should be treated as public.
Then detect and revoke fast. Defender for Cloud DevOps security surfaces exposed secrets across your connected repos, and a leaked key on public GitHub gets tested by scanners within minutes. Revoke first, investigate second.
Quick wins this week:
Enable GitHub push protection on every org repo, private included
Convert one CI/CD pipeline to workload identity federation
Find your oldest production secret and rotate it
How many of your service credentials have a named owner today?