← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Credential Layer Expansion Outpaces Security Visibility Amidst Accelerating Software Production

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GitHub commits increased from 1 billion in 2025 to 2.9 billion by August 2026.
  • GitGuardian found 28.65 million new hardcoded secrets in public GitHub in 2025.
  • Leaked AI service credentials rose by 81% in 2025.
  • The credential layer lacks a defined perimeter, complicating security.

Accelerated Software Development and Credential Growth

Software production is growing at a rate that exceeds the assumptions underlying many current security controls. GitHub reported an increase from approximately 1 billion commits in all of 2025 to 2.9 billion commits by August 2026, projecting an annualized rate of over 14 billion for the 2026 reporting year. This acceleration in code production directly correlates with an increase in infrastructure and the number of secrets generated.

Rising Credential Exposure

The expansion of applications, integrations, automations, and AI agents means more systems require authentication, exacerbating credential exposure. GitGuardian identified 28.65 million new hardcoded secrets in public GitHub commits in 2025, marking a 34% year-over-year increase. Notably, leaked credentials associated with AI services saw an 81% rise during the same period.

Challenges in Securing the Credential Layer

The 'credential layer' encompasses all credentials connecting individuals, applications, infrastructure, and services within an enterprise. This layer lacks a fixed perimeter, as credentials can spread from sanctioned cloud accounts to repositories, shared knowledge bases, or remain on developer laptops. Additionally, secrets can be created outside traditional security oversight through personal projects or new AI services, making comprehensive visibility difficult for security teams.

The Need for Detection and Visibility

Given the expanding and distributed nature of credentials, establishing immediate visibility into this layer is crucial for security teams. Effective credential-layer security begins with detection, as understanding the existence, location, and access scope of credentials is a prerequisite for subsequent remediation and prevention efforts.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 05

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The rapid acceleration of software production, evidenced by a significant increase in GitHub commits, is causing the credential layer to expand faster than security teams can monitor it. This growth leads to more exposed credentials, with GitGuardian detecting 28.65 million new hardcoded secrets in public GitHub commits in 2025, highlighting a critical need for enhanced visibility and security measures.