[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmsVChPClHYYCrsQg19jQGYFK0RMxOMrnmpncv5T13Mo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"36f1e1ef-7ded-4e4e-b8c2-d0cac1190359","ai-coding-agents-are-doubling-the-rate-of-secrets-sprawl","df8ac4e7-0819-468c-81ea-39659f372564","AI Coding Agents Are Doubling the Rate of Secrets Sprawl","AI coding agents are leaking credentials and secrets at approximately twice the rate of human developers, largely because they autonomously access and propagate sensitive information across multiple systems without adequate oversight. The core problem is that non-human identities — API keys, tokens, and credentials used by AI agents — are poorly tracked, rarely rotated, and often hardcoded into repositories or configuration files. As AI adoption accelerates, security teams are losing visibility into where secrets live and how they are being consumed. This represents a critical identity governance gap: organizations designed their secrets management practices around human developers, not autonomous AI systems operating at machine speed and scale.","**Immediate Actions:**\n- Deploy automated secrets scanning tools (e.g., GitGuardian, Trufflehog) across all code repositories and CI\u002FCD pipelines to detect exposed credentials in real time.\n- Audit all active non-human identities (API keys, service accounts, tokens) and immediately revoke any that are unused, overprivileged, or of unknown origin.\n- Enforce short-lived, auto-rotating credentials for all AI agents and automation pipelines using a centralized secrets manager (e.g., HashiCorp Vault, AWS Secrets Manager).\n\n**Long-Term Improvements:**\n- Establish a Non-Human Identity (NHI) governance program that tracks, inventories, and enforces least-privilege access for every AI agent and service account.\n- Integrate secrets detection as a mandatory gate in the software development lifecycle (SDLC) so no code containing hardcoded secrets can be merged or deployed.\n- Develop and enforce organizational policies specifically governing how AI coding assistants are permitted to handle, generate, and store credentials.\n\n**Detection & Monitoring Measures:**\n- Implement continuous monitoring and alerting for anomalous credential usage patterns, particularly for non-human identities accessing sensitive systems outside normal operational parameters.\n- Maintain a centralized audit log of all secrets access and rotation events to enable rapid forensic investigation when a leaked credential is detected.\n- Set up automated breach notification workflows that trigger immediate credential rotation whenever a secret is confirmed or suspected to be exposed.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 5: Account Management","CIS Control 16: Application Software Security","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 SI-12: Information Management and Retention","NIST SP 800-204D: Strategies for Securing AI\u002FML Pipelines","GDPR Article 32: Security of Processing","OWASP Top 10 A02:2021 – Cryptographic Failures","ITIL: Security Management \u002F Access Control Practices","published","2026-09-24T19:22:35.384156+00:00","2026-09-24T19:22:35.3+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fsecrets-sprawl-is-identity-problem-that.html","secrets-sprawl-is-an-identity-problem-that-ai-just-made-impossible-to-ignore-eeeda4","Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]