[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8GDDPIP6kgYhl_LVDLS3_raFJOCvLBpK7AlMmHsa1F8":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"df8ac4e7-0819-468c-81ea-39659f372564","Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore","secrets-sprawl-is-an-identity-problem-that-ai-just-made-impossible-to-ignore-eeeda4","AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI","A new report indicates that AI coding agents are contributing to a significant increase in secrets sprawl, leaking credentials at approximately twice the rate of human-written code. This acceleration is due to AI agents' ability to access and spread sensitive information across more systems than security teams can effectively track and rotate, highlighting a growing challenge in managing non-human identities.","AI coding agents are leaking secrets at twice the rate of human-written code.","Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore The Hacker NewsSep 24, 2026Artificial Intelligence \u002F Application Security AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI services, meaning the tools meant to advance development are also accelerating the exposure of the keys development relies on. This isn’t a new vulnerability; what is new is AI changing the scale and pace at which those mistakes can happen. A coding agent can read an entire project, modify files, generate configurations and interact with external services in the time a developer might take to review a single pull request. The main issue isn’t that AI agents sometimes encounter secrets but that many of those secrets were never designed for an environment in which software can act autonomously. AI coding agents are contributing to secrets sprawl by hardcoding credentials into more files and spreading existing ones into more systems than security teams can track and rotate. How secrets sprawl has changed in the agentic AI era Secrets sprawl occurs when credentials such as API keys, tokens and service account credentials accumulate across more systems than an organization can reliably inventory and rotate — hardcoded in source files, pasted into configurations and copied into tickets. Security teams have historically tried to control this sprawl by detecting exposed secrets retroactively; scanners watch repositories, pre-commit hooks catch what they can and security teams rotate credentials after an exposure is discovered. Those controls still matter, but AI agents expose the limitations of depending on detection alone. Agents can read local files, execute commands, call APIs, interact with Model Context Protocol (MCP) servers and modify configuration. Each additional capability creates another place where a credential may be required and another path through which that credential can spread. This is why organizations should treat secrets sprawl in the agentic AI era as a Non-Human Identity (NHI) problem, not a model-behavior one. Every useful action an agent takes on another system has an identity behind it. When agents query a database, call an API and deploy to staging, some credential authorizes that action. Organizations cannot reliably predict every action an autonomous system will take, but they can control what the identity behind that system is allowed to access. How AI coding agents can expose secrets What makes coding agents useful is also what creates new credential risks: agents need context. An agent that can’t read an entire project doesn’t provide much assistance, especially one that must be re-authorized for every operation. Below are several ways this plays out in practice, demonstrating why organizations should be more careful when granting AI coding agents access to credentials and secrets. Agents can access sensitive files in the project context Developers often keep credentials in .env files and local configurations, left behind from a prior debugging session and never intended for source control. An AI coding agent with broad access to a project may be able to read those files along with the application code it was asked to analyze. To an AI agent, a configuration file containing a production API key is still part of the working environment, so unless access is explicitly limited, the credential may become available to the agent even if it is irrelevant to the task. This shifts security assumptions around developer workstations: Local plaintext credentials are no longer accessible only to the developer and the applications that explicitly reference them but are now also potentially available to software agents operating across the same environment. Agent and MCP configurations can contain hardcoded credentials Setup instructions for agents and MCP servers routinely simplify how developers connect AI applications with databases, APIs and other external systems. Because many integrations require authentication, that simplification often means pasting the credential directly into a configuration file. Since that file never enters version control, it's easy to assume the credential is safe. However, the credential may still exist in plaintext on a developer machine, often in a location the agent has permissions to read. Secrets are duplicated across surfaces that teams may not scan A secret rarely lives in one location; the same key ends up in an .env file, a CI\u002FCD variable or even a Jira ticket while engineers troubleshoot a failed deployment. An AI coding agent connected to those systems introduces another vulnerability: since every copy of a secret authenticates, rotating the one in the repository leaves the rest working. This is why repository scanning alone cannot solve secrets sprawl. A large share of secret incidents can originate completely outside code repositories, with exposures in collaboration and ticketing tools, which is why rotating the copy found in a repository has minimal benefit if the same credential is valid elsewhere. Agent credentials are often over-permissioned An agent needs enough access to perform its work, creating pressure to grant broad permissions to ensure its tasks are useful. Permissions granted during prototyping to avoid errors may become part of a production process, so the original permissions with temporary intentions remain — no one revisits them once the workflow is running. The risk grows further in multi-agent systems. An orchestration layer holding keys for several agents may trigger a domino effect of compromised identities, with attackers inheriting access to everything the orchestrator was authorized to reach. The governance gap is already measurable. In Keeper Security’s RSAC 2026 survey, 46% of respondents said AI-powered tools have access to critical systems and sensitive data, yet 76% of respondents said those identities aren’t consistently governed under privileged access policies. Even when access is granted, the controls that normally accompany that level of access often don't exist. How to secure secrets in AI-assisted development Banning AI coding tools entirely isn’t realistic for most organizations, and it honestly isn’t necessary. Instead, organizations should view AI agents as another identity operating across development environments and grant access accordingly. Here are several ways to secure secrets in AI-assisted development: Remove static credentials from the developer environment: Instead of storing secrets in .env files, MCP configurations or IDE settings, organizations should retrieve secrets from a centralized secrets management platform when they are needed. If the plaintext credential is not on the workstation, an agent cannot accidentally read it from the developer environment. Replace long-lived keys with short-lived, automatically rotated credentials: A static key that leaks remains a liability for as long as it stays valid, which may be months or years. A short-lived credential that expires in minutes and rotates on a set schedule narrows that window substantially and removes the need to find every copy before an attacker does. Give every agent its own scoped identity: Shared service accounts make it nearly impossible to identify which agent performed which action, and they ensure that every agent inherits the broadest permission any of them needs. Organizations should give each AI agent only the permissions required for its task, and make those permissions temporary whenever possible. By treating an AI agent like a contractor, organizations let it handle specific resources and take specific actions within a defined perio","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fsecrets-sprawl-is-identity-problem-that.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEi8mLbRmwaAgvJunom4dBxBYMz50LUutLJiS6Yz7RPCbZQO1aYXAqFWOga4dCKD3AoenZHxYLpPexLEQ2swJO67vy4xl2_uw1g08lRtETN3hTMLpvafmn5WD4VK2ilpuFaYAdMHHPBRG2yYsyDBins15huubgt2b6pDVnnhW92It8lKHBqOifOLTaNSwho\u002Fs1600\u002Fkeeper.png","2026-09-24T11:00:00+00:00","2026-09-24T14:00:21.16801+00:00",8,[18,21,24],{"name":19,"type":20},"AI coding agents","product",{"name":22,"type":23},"GitGuardian","vendor",{"name":25,"type":26},"Artificial Intelligence","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,38],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]