#GitSecurity
I just published Git History Never Forgets: A Practical Guide to Scrubbing Secrets and PII medium.com/@sdntechdemo...
#GitSecurity #DevSecOps #NetworkAutomation #Cybersecurity #DevOps #sdntechforum
Git History Never Forgets: A Practical Guide to Scrubbing Secrets and PII
The irony hit on a Friday afternoon.
medium.com
September 22, 2026 at 5:04 PM
Clone2Leak Attacks: Exploiting Git Flaws to Steal Credentials

thedefendopsdiaries.com/clone2leak-a...

#clone2leak
#gitsecurity
#credentialleak
#potatosecurity
#infosec
#github
#vulnerability
#softwaresecurity
#authentication
#devsecops
January 29, 2025 at 4:40 AM
🔧 Configuración Errónea en Webhooks de AWS CodeBuild Puso en Riesgo Accesos de Admin

AWS corrigió fallos en filtros de webhooks que podían permitir acceso no autorizado

https://devops.com/aws-codebuild-webhook-misconfiguration-exposed-admin-access-risk/

#CodeBuild #CI_CD #GitSecurity #RoxsRoss
January 29, 2026 at 12:29 PM
Exposing AWS keys on GitHub? 🔑 Here's why git revert won't save you and the 3-step response to fix it. Rotate, clean, prevent! #AWS #GitSecurity #DevOps
Git Revert - Accidentally Pushed Secret Keys to GitHub? Here’s How to Fix It!
Don't waste hours scrubbing history while a live key is still active. Rotate first, clean second, and automate your protection for the future.
kodekloud.com
July 2, 2026 at 10:39 PM
August 26, 2026 at 1:18 PM
A scan found 28,000 exposed Git repositories leak credentials, API keys, and sensitive files. Learn how to secure your public web servers today.

#GitSecurity #DataLeak #PotatoSecurity #ClownSecurity
August 25, 2026 at 3:24 AM
a must-watch:
👉 https://lckhd.eu/IfZhTc

Have you set up commit signing yet? Drop a comment below! 👇

#GitSecurity #YubiKey #DevSecOps #SoftwareEngineering #SupplyChainSecurity #CyberSecurity #Developers (3/3)
August 2, 2026 at 8:10 AM
commit, not someone pretending to be you.

Watch this to see exactly why it matters 👇
https://lckhd.eu/4Ne2WE

#GitSecurity #YubiKey #DevSecOps #CyberSecurity #OpenSource (2/2)
July 30, 2026 at 7:00 AM
New security updates for Git address seven vulnerabilities in all previous versions. Stay protected and update now. #GitSecurity #VulnerabilityFixed https://github.blog/open-source/git/git-security-vulnerabilities-announced-6/
Git security vulnerabilities announced
Today, the Git project released new versions to address seven security vulnerabilities that affect all prior versions of Git.
github.blog
July 17, 2025 at 6:31 PM
AI coding models often embed hardcoded credentials from training on public repos, exposing secrets in source files and git history. Tools like Gitleaks and TruffleHog help detect and manage these risks. #GitSecurity #SecretManagement #USA
Hardcoded Secrets in AI-Generated Code: Catch Them Before Git Does
AI coding models frequently insert hardcoded credentials into generated code because they learned "working" patterns from public repositories, which puts secrets into source files, git history, and client-side bundles. Prevent with a fast pre-commit scanner and deep-history verification—Gitleaks blocks commits while TruffleHog scans history and verifies live credentials to prioritize rotation. #Gitleaks #TruffleHog
www.hendryadrian.com
April 6, 2026 at 2:40 PM
June 12, 2026 at 7:24 AM
CRITICAL: SSRF in charmbracelet soft-serve (0.6.0 – 0.11.4) lets SSH users access internal services via crafted LFS endpoints. Upgrade to 0.11.4+ now! https://radar.offseq.com/threat/cve-2026-30832-cwe-918-server-side-request-forgery-01aea4d4 #OffSeq #SSRF #GitSecurity
CVE-2026-30832: CWE-918: Server-Side Request Forgery (SSRF) in charmbracelet sof
The vulnerability CVE-2026-30832 affects charmbracelet's soft-serve, a self-hosted Git server designed for command-line use. Versions from 0.6.0 to before 0.11.4 contain a Server-Side Request Forgery (SSRF) flaw categorized under CWE-918. A
radar.offseq.com
March 8, 2026 at 7:00 AM
January 15, 2026 at 1:00 AM
Git vulnerability found: RCE during clone via malicious submodules. Issue: Git mishandles carriage returns in paths, leading to writing data to unintended locations and enabling malicious hook execution. #GitSecurity 1/6
July 9, 2025 at 4:00 PM
How I Made $64k from Deleted Files — A Bug Bounty Story

Earned $64k by scanning GitHub repos for secrets in deleted files, blobs, and .pack files

https://medium.com/@sharon.brizinov/how-i-made-64k-from-deleted-files-a-bug-bounty-story-c5bd3a6f5f9b

#BugBounty #GitSecurity
May 16, 2025 at 5:30 AM
Learn how to effectively use Git push protection to remove secrets from your codebase the right way! Enhance security on Azure Active Directory with key strategies. #Cybersecurity #GitSecurity
dev.to
January 3, 2026 at 12:15 AM