Software production is growing at a rate that exceeds the assumptions underlying many current security controls. GitHub reported an increase from approximately 1 billion commits in all of 2025 to 2.9 billion commits by August 2026, projecting an annualized rate of over 14 billion for the 2026 reporting year. This acceleration in code production directly correlates with an increase in infrastructure and the number of secrets generated.
The expansion of applications, integrations, automations, and AI agents means more systems require authentication, exacerbating credential exposure. GitGuardian identified 28.65 million new hardcoded secrets in public GitHub commits in 2025, marking a 34% year-over-year increase. Notably, leaked credentials associated with AI services saw an 81% rise during the same period.
The 'credential layer' encompasses all credentials connecting individuals, applications, infrastructure, and services within an enterprise. This layer lacks a fixed perimeter, as credentials can spread from sanctioned cloud accounts to repositories, shared knowledge bases, or remain on developer laptops. Additionally, secrets can be created outside traditional security oversight through personal projects or new AI services, making comprehensive visibility difficult for security teams.
Given the expanding and distributed nature of credentials, establishing immediate visibility into this layer is crucial for security teams. Effective credential-layer security begins with detection, as understanding the existence, location, and access scope of credentials is a prerequisite for subsequent remediation and prevention efforts.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The rapid acceleration of software production, evidenced by a significant increase in GitHub commits, is causing the credential layer to expand faster than security teams can monitor it. This growth leads to more exposed credentials, with GitGuardian detecting 28.65 million new hardcoded secrets in public GitHub commits in 2025, highlighting a critical need for enhanced visibility and security measures.