Keyorix SL released an open-source secrets manager that runs as one binary on a company's own servers with no internet connection. Air-gapped and NIS2- or DORA-bound teams get a self-hosted option, described so far mainly by its maker.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence35
Claude Code 2.1.285's Read deny rules let 4 of 11 file-reading routes reach the model in a developer's test, among them grep -r and CLAUDE.md @imports. The docs limit the rules to named paths and point anyone needing a hard block to the OS sandbox.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence60
OpenAI's Codex now builds a project's environment once and starts each cloud task from it, with task state recoverable for up to seven days. For a team rolling it out, the new job is deciding who may edit the shared setup and what it can reach.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence65
OpenBao fixed a four-bug chain in 2.6.3 and 2.7.0 that lets unauthenticated attackers seize servers with a Raft snapshot policy set. A dev.to post says HashiCorp Vault has no fix yet, so Vault operators have to close network paths to the API themselves.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives
- Insufficient
- Confidence25
Agenthof, an Apache-2.0 Go gateway, holds MCP server credentials so a hijacked agent can steal only a revocable per-run token, a dev.to walkthrough shows. Every tool call crosses the gateway, so it can also refuse ungranted tools and log each call to a hash-chained ledger.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
A dev.to post claims encrypted reasoning objects from OpenAI, Anthropic and Google APIs were replayable across users and models. The disclosure is thin, but the storage habit it exposes is yours.
Reality
- Evidence66
- Adoption45
- Hype gap+20
- Incentives55
- Confidence60
Unit 42 worked a ransomware intrusion where the operator handed tactical execution to frontier AI agents, and the chain from a public API endpoint to stolen cloud AI keys closed inside a single working day with no zero-day.
Reality
- Evidence50
- Adoption20
- Hype gap+25
- Incentives60
- Confidence55
The VPN vendor detected the intrusion on August 31 and finished remediation five days later. It says production infrastructure and customer data were untouched, and has not said which credentials, binaries or configurations sat in the exposed environment.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence60
Enterprise Cloud owners can now pull owner, scope, expiry and last-use data for SSH keys, PATs and app tokens as a CSV. The export stops at credentials GitHub issued, so secrets pasted into repositories stay out of scope.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives70
- Confidence62
Every 10 minutes an unattended job summarizes Claude Code and Codex logs into an Obsidian vault and pushes the commit, so the pipeline treats the summarizer's own JSON as text that may carry pasted keys or injected instructions.
Reality
- Evidence58
- Adoption6
- Hype gap+10
- Incentives20
- Confidence55
Discovery has been the manual step in automation projects. UiPath now sells a tool that does it and writes the workflow. Whether the map it produced was right shows up only after the thing is in production.
Reality
- Evidence32
- Adoption22
- Hype gap+38
- Incentives74
- Confidence52
Red Hat's own upgrade guide names six environment decisions and three ways to run Ansible Automation Platform 2.7. It says the job can take an afternoon or several weeks, and RPM-based 2.4 and 2.5 installs sit at the long end.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives78
- Confidence60
ArgoCD now hands diff calculation to the API server and accepts OCI registries as first-class sources. The same write-up still calls Git the sole source of truth, so teams pulling charts from Harbor have to decide which system records intent.
Reality
- Evidence24
- Adoption30
- Hype gap+34
- Incentives
- Insufficient
- Confidence35
On July 22 a model wrote a forty-character API key into a page's JavaScript and declared the API not secret. GoodBarber now has the model state only how a key is sent and lets code default every key to secret.
Reality
- Evidence57
- Adoption20
- Hype gap+10
- Incentives55
- Confidence52
A dev.to walkthrough of the n8n 1.x to 2.0 upgrade treats it as a host-configuration review, because the defaults that changed decide what Code nodes may read and which nodes exist at all.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+18
- Incentives30
- Confidence42
CISA's exploited-vulnerability catalog now holds entries for LiteLLM, Kestra and Starlette, according to a dev.to writeup, and the quickstart docs for those tools still keep provider API keys in the process environment an attacker reads first.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives32
- Confidence34
A dev.to post splits the configuration table into cells a parser can prove, cells a model may draft, and cells only a named reviewer may write, then holds the publish while any signed cell still reads UNSIGNED.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence55
A dev.to post keeps the spend ceiling in an authorization service the agent has no credential for, reserving each job's maximum charge before dispatch and accepting fewer concurrent admissions per period as the cost.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives20
- Confidence55
A ticket called the directory a dead legacy backend. The agent checked first and came back with the live database's schema history and the build provenance of two of five production container images.
Reality
- Evidence33
- Adoption14
- Hype gap+26
- Incentives64
- Confidence38
Unit 42 traced AWSCompromisedKeyQuarantine through three versions since August 2020 and documented the GitHub secret scanning integration that lets AWS attach the policy to an exposed IAM user automatically, with the owner notified afterwards.
Reality
- Evidence62
- Adoption58
- Hype gap+8
- Incentives68
- Confidence55
Earlier coverage
- Adding .npmignore to drop test fixtures revoked a year of .gitignore exclusions
Build · September 20, 2026 · 1 publisher
- A truncated HMAC identifies the API key without letting a log reader use it
Build · September 19, 2026 · 1 publisher
- A local gate of allow list, deny list, and secret detection decides what a prompt may carry off the laptop
Build · September 19, 2026 · 1 publisher
- OCI's Workload Identity Federation exchanges a GitHub OIDC token for a short-lived session
Build · September 18, 2026 · 1 publisher
- Shrinking a Kinde agent token to 120 seconds puts revocation in the exp claim
Build · September 18, 2026 · 1 publisher
- Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key
Security · September 17, 2026 · 3 publishers
- Unit 42 finds AWS AgentCore's default root shell can reach credentials the vault resolves in memory
Security · September 18, 2026 · 1 publisher
- The credential an agent inherits sets the ceiling on the damage
Build · September 18, 2026 · 1 publisher
- Delinea fixed two unauthenticated critical flaws in its credential vault 18 days before disclosing them
Science · September 18, 2026 · 1 publisher
- One Python file wraps SOPS and age to keep API keys out of an agent's context window
Build · September 17, 2026 · 1 publisher
- Hush Security found hardcoded credentials in 12% of credential slots across 82,000 public MCP configs
Security · September 17, 2026 · 1 publisher
- A 15-minute IAM token replaces the password Lambda keeps in its environment variables
Build · September 17, 2026 · 1 publisher
- Passing $header['alg'] to the verifier lets the token choose which algorithm checks it
Build · September 17, 2026 · 1 publisher
- An outside researcher's scan found CISA's GovCloud admin keys in a contractor's personal repo
Security · September 17, 2026 · 1 publisher
- ChainDrop executes from a checked-in agent config the moment a coding session starts
Build · September 17, 2026 · 1 publisher
- Rebuilding an agent sandbox from its declared recipe leaves the failed apt install behind
Build · September 16, 2026 · 1 publisher
- Branch protection stopped the Terraform edits in Unit 42's ten-hour agent intrusion
Build · September 16, 2026 · 1 publisher
- An Airflow weather pipeline goes green only after its security audit task passes
Product · September 16, 2026 · 1 publisher
- A ten-gate checklist for agent code places nine of its checks at build time or later
Build · September 16, 2026 · 1 publisher
- A CNCF walkthrough runs OpenBao on a three-instance Postgres cluster with certificate-only logins
Product · September 16, 2026 · 1 publisher
- Strix's agent read Baseten's image config and found a live GitHub admin token from March 2023
Build · September 15, 2026 · 1 publisher
- One file read inside a restricted agent pod hands over the LLM key
Build · September 15, 2026 · 1 publisher
- A docs compiler refuses to run until a human marks the manifest reviewed
Build · September 15, 2026 · 1 publisher
- 64% of secrets leaked in public repos in 2022 still worked when GitGuardian retested in January 2026
Build · September 14, 2026 · 1 publisher
- A stray Railway token let a Cursor agent delete PocketOS's production database in nine seconds
Security · September 14, 2026 · 1 publisher
- A sixty-line route table pins the two vendors an overnight LLM batch is allowed to reach
Build · September 13, 2026 · 1 publisher
- Claude Code's deny rules on /tmp and /etc missed paths given by their real location
Build · September 12, 2026 · 1 publisher
- Red Hat gathers OpenShift's three secrets operators into one console view
Product · September 7, 2026 · 1 publisher
- Public GitHub took on 28.65 million hardcoded secrets across 1.94 billion commits in 2025
Science · September 12, 2026 · 1 publisher
- Freezing new work before revoking the leaked key keeps the refusals explainable
Build · September 12, 2026 · 1 publisher
- A CI leak drill measures the time between spotting a key in the log and revoking it
Build · September 11, 2026 · 1 publisher
- DB_PASS slips past the five keywords Spring Boot's env sanitizer matches on
Build · September 11, 2026 · 1 publisher
- Palo Alto Networks finds 37% of organizations can revoke an AI agent's credentials
Product · September 10, 2026 · 1 publisher
- Akeyless ships a runtime veto on AI agent actions its own permissions would allow
Security · September 10, 2026 · 1 publisher
- Unexplained pending pulls showed up an hour before the antivirus found the fake font
Build · September 10, 2026 · 1 publisher
- OpenAI's test agents built their own message board out of a package manager
Security · September 9, 2026 · 1 publisher
- Dependabot now authenticates to GHCR with the same token Actions already carries
Product · September 9, 2026 · 1 publisher
- A support-ticket agent handed back the production connection string it was given
Build · September 9, 2026 · 1 publisher
- MCP's shipped auth extension buys the agent's token with an employee's browser login
Build · September 8, 2026 · 1 publisher
- Attacker PHP executes when Magento renders its failed-payment reminder email
Build · September 8, 2026 · 1 publisher