
Security teams gain a usable inventory of the credential layer when discovery runs across every place a secret can land, including repositories, public exposure, developer endpoints, and the new authentication paths introduced by AI agents. The challenge is that the surface is growing faster than the controls designed to watch it. Software production has moved from roughly 1 billion commits across all of 2025 to a pace of 2.9 billion in August 2026, an annualized rate of more than 14 billion for the 2026 reporting year. Platform engineering teams are already planning for infrastructure that needs to handle 30 times today’s scale as agentic development takes hold. Every additional application, automation, and agent extends the credential layer further and raises the cost of waiting.
Why the credential layer has no convenient perimeter
The credential layer is the collection of secrets that connects people, applications, infrastructure, and services across an enterprise. Its perimeter follows the credentials themselves rather than the network. A key created inside a sanctioned cloud account can later appear in plaintext in a repository or a shared knowledgebase. A credential stored in an approved vault can have plaintext copies sitting on a developer’s laptop. Other secrets are created entirely outside the security team’s normal vantage point through a personal project or a newly adopted AI service, particularly by the growing number of citizen developers who now have access to coding agents. The result is an attack surface that crosses every technology and ownership boundary.
Internal repositories are roughly six times more likely than public repositories to contain at least one secret. Around 28% of secrets incidents originated entirely outside source-code repositories, inside collaboration and productivity systems. Each scanner, vault, repository, or endpoint describes the part of the credential layer it can see, but no single source covers the whole population.
What each discovery source actually reveals
Source control remains essential because hardcoded credentials leave durable evidence. A credential removed from the current version of a file can still sit in Git history, branch into other repositories, and end up beyond the organization’s control once it reaches a public setting.
Internal repositories expose another large population. They contain the credentials developers and applications use during normal work, including access to cloud environments and internal services.
Collaboration systems expose a different part of the layer. Credentials get pasted into tickets while troubleshooting, move through chat during handoffs, and can remain searchable long after the task that introduced them is finished.
Why the developer laptop is now part of the credential perimeter
Until recently it was considered normal to use local environment files for application secrets and to let command-line tools cache credentials used to reach cloud services. The danger of an unscrubbed local shell history, which can preserve values long after the user has forgotten they were entered, seemed low. That changed when attackers shifted their attention to the endpoint. The end of 2025 brought new waves of infostealer activity, including Shai-Hulud and S1ingularity, which turned the developer laptop into a target and an entry point into the supply chain. Every laptop is part of the credential layer, and the secrets on those machines need to be mapped.
Repository scanning shows credentials that reached source control. Public monitoring reveals exposures outside corporate repositories. Endpoint discovery identifies secrets that may never have entered a centrally monitored system. The credential layer only becomes visible when those perspectives are connected.
How attackers already search across those boundaries
Compromised credentials already accounted for 22% of initial access, according to the 2026 Verizon Data Breach Investigations Report. The same research found corporate credentials on unmanaged devices driving a significant number of the breaches studied, with the reporting window ending before the information stealer disturbances observed in early 2025 became widespread.
Self-propagating malware running on an endpoint can search browser stores, local files, and application storage. It can take any authentication material it finds without regard for which team created it or which security product was supposed to govern it. Developer systems offer especially valuable targets. A developer machine may authenticate to source control and cloud infrastructure, and it can also hold local credentials for applications under development. Compromising that endpoint can expose access that spans several otherwise separate parts of the enterprise.
The developer laptop is now shared with a new kind of user
AI agents can read files, execute commands, and interact with external services. Model Context Protocol connections can give those agents access to additional tools, and each connection introduces another place where authentication and authorization need to be established.
Analysis of systems compromised during the Shai-Hulud 2 supply-chain campaign provides a rare view into the density of credentials on these machines. Across 6,943 compromised systems, 33,185 unique secrets were identified. Forty-four percent of compromised machines held more than 10 secrets, while 5% contained more than 100.
The way AI agents are authenticated has opened a parallel gap. The same research recorded 24,008 unique secrets in public MCP configuration files during 2025, of which 2,117 could be verified as valid. A security team that scans repositories can know a great deal about repositories, and still has limited visibility into credentials living on the machines where code is created, tested, and connected to external systems.
Why every credential needs surrounding context
Finding a secret provides the first coordinate. Security teams need to know whether it is still valid, how long it has been exposed, and where it is used to understand the risk it represents.
Validity is one of the most immediate signals, and most secrets stay valid far longer than they should. Ideally any credential would be created just in time and expire after use, but retesting of credentials confirmed valid in 2022 found that 64% were still valid in January 2026. A secret can stay useful to an attacker for years after the original exposure.
A secret’s location adds another dimension. A credential found once in an internal repository has one exposure history. The same credential appearing on a laptop and later in a public repository has traveled much farther, and every occurrence expands the set of people and systems that may have had access to it. Credential fingerprinting can connect those appearances while preserving a single credential record, so seven detections of the same secret represent one credential with seven known exposures.
Ownership connects the finding to the team responsible for managing the access, identifying what policy or governance it falls under rather than only who created it. The scope of permissions shows what the credential can do, distinguishing a credential limited to a development service from one present in production with broad administrative permissions. Validity and permission context together reveal which findings deserve the fastest attention. Dependencies complete more of the picture, because a credential can be highly exposed while still supporting critical workloads, and understanding those relationships gives the organization the data it needs to rotate or revoke the credential safely.
Why security teams need a real denominator for coverage
Many enterprises already have strong secrets-management programs, and those systems provide valuable information about credentials already under management. The larger credential layer mapping determines how complete that coverage really is. A company might have 50,000 credentials stored in approved vaults while thousands more sit in plaintext in repositories, developer endpoints, or collaboration systems. Vault reporting shows how the known secrets are accounted for, blind to the ones created outside the planned paved paths.
Security teams need to know how much of the credential population has an identified owner. They need to know how many active credentials can be connected to permissions and dependent workloads, and they need visibility into which credentials have crossed into public environments. Those measurements depend on discovering the population first.
Why defenders need to move at machine speed
Secret exposure has grown 1.6 times faster than the number of active developers over the period tracked by recent industry research. Attackers are moving faster as well, with an average eCrime breakout time of 29 minutes in 2025 and the fastest observed case reaching lateral movement in 27 seconds. Defenders need to react at machine speed, because the days of a human executing an attack are past. The time available to respond will only continue to shrink, and the answer cannot be faster reaction alone. It requires a shift toward prevention, which is only possible once the organization understands the surfaces where credentials can leak.
How a detection-first approach builds the map for everything else
Remediation and prevention depend on having an inventory. Vault reporting becomes one measurement inside that larger picture. Repository findings become another. Endpoint discoveries add credentials that may have remained invisible to central security systems. Together they create a usable map of the credential layer. Discovery across repositories, public exposure, and developer endpoints produces the first coordinate for every secret, and combining those perspectives is what turns partial views into coverage a security team can actually measure.
FAQ
What is the credential layer?
The credential layer is the collection of secrets that connects people, applications, infrastructure, and services across an enterprise. Its perimeter follows the credentials themselves rather than the network, which means a single secret can appear across sanctioned clouds, developer laptops, repositories, and collaboration tools at the same time.
Why are developer laptops now part of the credential perimeter?
Info-stealer campaigns such as Shai-Hulud and S1ingularity turned developer endpoints into active targets and entry points into the supply chain. Analysis of systems compromised during the Shai-Hulud 2 campaign found 33,185 unique secrets across 6,943 compromised machines, with 44% of compromised machines holding more than 10 secrets.
How fast are software production and credential exposure growing?
Annual commit volume moved from roughly 1 billion across all of 2025 to a pace of 2.9 billion in August 2026, and platform engineering teams are already designing for 30 times today’s scale. Over the tracked period, secret exposure has grown 1.6 times faster than the number of active developers.
This article summarizes reporting from thehackernews.com.
