Topic: secrets management
-
Conjur: Open-Source Secrets Management for Secure Apps
Conjur is an open-source secrets management solution that provides a centralized, policy-driven system to securely control access to credentials like passwords and API keys, eliminating the risks of hardcoding them in code or config files. It operates on a core philosophy of identity and policy, ...
Read More » -
Azure AD Credentials Leaked in Public App Settings
A critical vulnerability in Azure Active Directory was discovered, where credentials were exposed in public configuration files, allowing potential exploitation. Attackers could use these credentials to impersonate trusted applications, gaining unauthorized access to sensitive data and systems wi...
Read More » -
AI Agents Cause 76% Surge in NHIs, Revealing Governance Gaps
A 2026 survey finds a rapid increase in non-human identities (NHIs), like AI agents and API keys, with 76% of organizations reporting a significant expansion of their digital attack surface. The rise of autonomous AI agents, used by 74% of organizations, introduces a potent new risk due to their ...
Read More » -
Master Zero Trust & Identity at Today's Virtual Summit
The SecurityWeek Zero Trust & Identity Strategies Summit 2025 is a virtual event focusing on modern cybersecurity frameworks and the evolution of Zero Trust into a core strategy for protecting corporate assets. Zero Trust Network Access (ZTNA) is highlighted as essential for strengthening access ...
Read More » -
How MCP Server Flaws Escalate to Supply Chain Attacks
A path traversal vulnerability in Smithery.ai's MCP server platform exposed administrative credentials, compromising over 3,000 AI servers and risking a major supply chain incident. The flaw allowed attackers to access sensitive files and an overprivileged token, enabling potential code execution...
Read More » -
Gootloader Evades Detection With 1,000-Part ZIP Archives
Gootloader malware now uses massively concatenated ZIP archives, a technique designed to crash common analysis tools and evade detection by exploiting parser vulnerabilities. The attack employs multiple evasion layers, including corrupted archive structures and unique file generation per download...
Read More »