HomeLatest NewsCyber SecurityAI firms risk data exposure through leaked credentials on GitHub, says Keeper Security CISO

AI firms risk data exposure through leaked credentials on GitHub, says Keeper Security CISO

Keeper Security’s CISO warns that leaked credentials on GitHub expose AI companies to growing cybersecurity risks, stressing stronger visibility, control and identity management for machine-based access.

Preferred Source of Google

Leading artificial intelligence companies have been found leaking sensitive credentials on GitHub, underscoring the growing risk of unmanaged machine identities as AI and automation expand, according to Shane Barney, Chief Information Officer at Keeper Security.

Barney was responding to a recent report by Wiz that identified exposed keys, tokens and other secrets across major AI developers. He said such exposures reveal how quickly machine-to-machine connections can grow as development scales and automation deepens.

“Each of these credentials represents an access pathway that, if left unsecured, can expose sensitive systems or data,” Barney said. He noted that as organisations adopt AI and cloud-native development, the number of non-human accounts continues to increase, often beyond the reach of conventional identity and access management systems.

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

Barney said that when visibility into machine-based credentials is limited, risk spreads quietly across otherwise well-protected systems. He called for sustained visibility and control through enterprise-wide secrets management, continuous monitoring and automated credential rotation.

“Reducing that risk requires continuous oversight and least-privilege access policies that contain exposure without slowing ,” he said. “Treating machine-based credentials with the same rigour applied to human users strengthens both resilience and operational trust.”

He added that combining Privileged Access Management with secrets management could further improve governance by enforcing strict access boundaries and accountability for elevated permissions.

Advertisement

“The Wiz findings serve as a reminder that as technology becomes more intelligent and interconnected, security must advance at the same pace,” Barney said. “The fundamentals still apply: know what identities exist, understand what they can access and ensure those privileges are tightly governed.”

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

OpenAI Faces Product Liability Lawsuit Over Alleged ChatGPT Harm

Paul Hebert has filed a 54-page civil complaint against OpenAI and Sam Altman in San Francisco Superior Court, alleging the company's ChatGPT product caused documented psychological harm during 2025.

RELATED ARTICLES