AI coding is fueling a secrets-sprawl crisis few CISOs are containing
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
AI-assisted and vibe coding is dramatically accelerating secrets sprawl, with GitGuardian reporting a 34% increase in leaked secrets on GitHub in 2025 — the largest spike on record — totaling nearly 29 million exposed credentials. Over 1.27 million AI-related secrets were exposed, an 81% year-over-year increase. Security leaders warn that the core problem is not detection but governance: 64% of valid secrets found in 2022 remain unrevoked in 2026. CISOs are advised to treat secrets sprawl as a non-human identity (NHI) governance challenge, enforcing ownership, adopting short-lived credentials, preferring workload identity over static API keys, and embedding security controls across the full SDLC rather than bolting them on afterward.