15 servers ask for keys issued by someone else: GitHub write tokens, Atlassian API tokens, Cloudflare DNS-edit tokens.
no tools were called. schemas only.
https://t.co/12Iex8M2W1
sent one initialize request to every remote server in the official MCP registry.
22,027 answered. 71.3% opened a session with no header auth.
most of them didn't skip auth. they moved it into tool arguments.
3,705 credential fields in tool input schemas. api_key, access_token, password.
3 of them are marked writeOnly or format: password.
a tool argument is written by the model, so the key has to enter the conversation first.
We graded by privilege, not count. Privilege scope was verified for 7,468 of 23,912—the rest stayed blank instead of marked as zero.
Being unindexed is not being secured.
Full writeup: https://t.co/inpnKssUWH
Swept 33 public attack surfaces. Found 23,912 active machine credentials.
ChatGPT share links, .mcp.json configs, AWS ECR Public layers—all downloadable without login.
1,277 keys could mint their own replacement keys. Revoking the leaked key changes nothing.
148 Alibaba Cloud keys returned 403 ("registered as leakage risk") from RAM.
Same key, STS endpoint: 200 OK.
Detection and enforcement paths were not wired together.
our secret scanner said 14,000 findings.
we asked each one a narrower question: does this credential work right now?
sent it to the issuing service, read the response body, not the status code.
525 came back alive.
detection counts candidates. verification counts exposure.
our secret scanner said 14,000 findings.
we asked each one a narrower question: does this credential work right now?
sent it to the issuing service, read the response body, not the status code.
525 came back alive.
detection counts candidates. verification counts exposure.
our secret scanner said 14,000 findings.
we asked each one a narrower question: does this credential work right now?
sent it to the issuing service, read the response body, not the status code.
525 came back alive.
detection counts candidates. verification counts exposure.
"don't touch it — it's load bearing"
somebody typed that about a credential this month.
committed 2019. owner: guessed. vault: no match. expires: never.
so we gave it a face 🐈⬛
#NHI#DevSecOps
6/ Stop building quieter dashboards with arbitrary filters. Shift to validation-first detection.
Read the full technical guide 👇 https://t.co/WMMKIpALMN
Your secret scanner isn't broken. The 10,000 false alarms burying the one real leak are.
New breakdown on the root causes of secret scanning false positives—and why an HTTP 200 OK never proves a key is actually live. 👇
🔗 https://t.co/WMMKIpALMN
5/ Trap #2: Misidentifying "indeterminate" states. When verification fails (e.g., rate-limited), automation often defaults to "revoke it." Now your security scanner just broke production.
Key rule: Never automate actions on indeterminate results.
4/ Trap #1: Relying on HTTP status codes. Plenty of APIs return 200 OK for invalid keys or public endpoints. Real validation inspects the response body, not just the status line.
3/ The core issue? Treating all false positives the same. There are actually two distinct types: • A string that was never a secret (UUIDs, commit SHAs) • A REAL credential that can't do harm (revoked, expired, test keys)
Fix them differently.
2/ Because alert fatigue is real. Over 12M+ exposed secrets were detected on public GitHub in a single year alone. No team can manually triage that volume.
When everything is flagged as high priority, nothing is.
1/ Secret scanning has a strange paradox: detection tools are faster than ever, yet leaked credentials still stay live in production for months.
Why? 🧵
Your secret scanner isn't broken. The 10,000 false alarms burying the one real leak are.
New breakdown on the root causes of secret scanning false positives—and why an HTTP 200 OK never proves a key is actually live. 👇
🔗 https://t.co/WMMKIpALMN
A leaked Slack webhook is a low-severity risk. Until an AI agent reads that channel.
Attackers can inject commands (OWASP LLM01), turning a write-only primitive into remote tool execution.
Wiring AI to a channel silently re-rates all its credentials. The fix is at the agent.