AI coding is fueling a secrets-sprawl crisis few CISOs are containing

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

AI-assisted and vibe coding is dramatically accelerating secrets sprawl, with GitGuardian reporting a 34% increase in leaked secrets on GitHub in 2025 — the largest spike on record — totaling nearly 29 million exposed credentials. Over 1.27 million AI-related secrets were exposed, an 81% year-over-year increase. Security leaders warn that the core problem is not detection but governance: 64% of valid secrets found in 2022 remain unrevoked in 2026. CISOs are advised to treat secrets sprawl as a non-human identity (NHI) governance challenge, enforcing ownership, adopting short-lived credentials, preferring workload identity over static API keys, and embedding security controls across the full SDLC rather than bolting them on afterward.

8m read timeFrom csoonline.com
Post cover image
139 Impressions