Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
DarkSword iOS Exploit Steals Crypto Wallet Recovery Phrases via Coruna Malware
October 8, 2026
Microsoft Teams Fights Deepfakes With AI-Powered Audio and Video Detection
October 8, 2026
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Home/CyberSecurity News/GitHub AI Scans Code for Hidden Passwords Before Commits
CyberSecurity News

GitHub AI Scans Code for Hidden Passwords Before Commits

Key Takeaways GitHub has launched a new AI-powered ModernBERT classifier to detect hidden passwords within code before commits. This enhancement expands secret protection beyond traditional pattern...

Jennifer sherman
Jennifer sherman
October 8, 2026 4 Min Read
2 0

Key Takeaways

  • GitHub has launched a new AI-powered ModernBERT classifier to detect hidden passwords within code before commits.
  • This enhancement expands secret protection beyond traditional pattern matching, aiming to significantly reduce the number of exposed credentials.
  • The feature is currently in private preview and will be rolled out to GitHub Secret Protection customers on Enterprise Cloud and GitHub Team plans in October, utilizing AI credits.
  • It processes potential secrets in under two milliseconds, addressing the increasing volume of code generated by developers and AI agents.

GitHub Leverages AI to Bolster Pre-Commit Secret Detection

GitHub, in collaboration with Microsoft Applied Sciences, has unveiled an advanced AI-driven solution designed to identify and block hidden passwords before code is committed to repositories. This new ModernBERT classifier represents a significant evolution in push protection, moving beyond the limitations of traditional pattern-based secret scanning.

Table Of Content

  • Key Takeaways
  • GitHub Leverages AI to Bolster Pre-Commit Secret Detection
  • Addressing the AI-Driven Code Explosion
  • Speed, Accuracy, and Impact on Development
  • What You Should Do

The company asserts that this AI system can scrutinize batches of potential secrets in less than two milliseconds, with the potential to more than double the number of credentials prevented from entering codebases. This initiative, announced on October 7, directly addresses the growing disparity between rapid software development cycles and the imperative for robust credential security.

Addressing the AI-Driven Code Explosion

Microsoft data indicates that approximately one-third of all GitHub pull requests now involve an AI agent. As both human developers and AI tools accelerate code generation, the demand for security checks that are both fast and accurate, without impeding development workflows or necessitating extensive manual reviews, has become critical.

Traditional secret scanning methods typically rely on identifying predefined patterns, such as specific token prefixes or fixed string structures. While effective for many API keys, these methods often fail to detect internal database passwords or other credentials that resemble ordinary strings. The new ModernBERT classifier overcomes this limitation by analyzing the contextual code surrounding a value, enabling it to determine whether a string is likely a credential rather than merely evaluating its format.

GitHub has provided examples demonstrating the model’s capability to pinpoint password-like values embedded in database URLs, Kubernetes Secret manifests, and Dockerfiles, while accurately disregarding placeholder strings like “changeme.”

Speed, Accuracy, and Impact on Development

Unlike generative AI models, this classifier’s function is purely evaluative, classifying candidate secrets rather than creating code. This specialized role makes it exceptionally well-suited for the rapid, on-the-fly checks required during a push attempt. It is important to note that the reported processing speed applies to batches of candidates, not an entire repository scan.

Accuracy is paramount in such systems, as false positives can disrupt development and erode trust in security warnings. GitHub states that its new classifier offers greater precision than its existing large language model pipelines, all while maintaining the speed and cost-efficiency necessary for integration into push protection. However, specific numerical false-positive rates were not disclosed in the announcement.

A review of nine quarters, from Q2 2024 to Q2 2026, revealed a 2.84-fold increase in screened public pushes, alongside a 2.59-fold increase in pushes containing supported credentials. Despite this surge in activity, GitHub found no statistically significant trend in the proportion of pushes containing secrets. Encouragingly, developer overrides of push-protection blocks decreased from 6.63% to 3.93%. These findings suggest that the increased workload stems from heightened development activity rather than a decline in developer vigilance.

Across the broader spectrum of secret types GitHub detects, push protection currently prevents approximately 30% of secrets from entering repository history. The remaining 70% are typically discovered post-commit.

Manual revocation of exposed secrets is a time-consuming process, averaging around 40 days, with about one in five secrets taking over 90 days to address. This highlights that detection alone does not resolve access issues, underscoring the critical need for proactive prevention.

The AI-based push protection is currently in private preview. GitHub plans a broader rollout later in October for GitHub Secret Protection customers on Enterprise Cloud and GitHub Team plans, where it will consume AI credits. Organizations already utilizing AI secret detection will be automatically upgraded, and post-push alerts will continue to be provided without additional cost.

Future plans include public preview alerts in Enterprise Server 3.23, extending to air-gapped environments, and integration with Copilot CLI and the Copilot App’s /security-review command.

It is crucial to remember that prevention of new leaks does not mitigate the risks from past exposures. GitHub’s secret scanning partner program facilitates the reporting and revocation of credentials by providers. For security teams, blocking new vulnerabilities and revoking access to previously exposed secrets remain distinct but equally essential tasks.

What You Should Do

  • If you are a GitHub Secret Protection customer on Enterprise Cloud or GitHub Team plans, prepare for the automatic upgrade to AI-based push protection and budget for AI credits.
  • Ensure your development teams are aware of the enhanced pre-commit secret detection capabilities and encourage their use to prevent credential leakage.
  • Even with enhanced prevention, regularly audit your repositories for historically exposed secrets and work with your providers to revoke compromised credentials promptly.
  • Integrate secret scanning and push protection into your CI/CD pipelines as early as possible to minimize exposure windows.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CybersecuritySecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

FBI and Ghana Police Bust Cybercrime Ring, Seize 300+ Devices

Next Post

Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub AI Scans Code for Hidden Passwords Before Commits
October 8, 2026
FBI and Ghana Police Bust Cybercrime Ring, Seize 300+ Devices
October 8, 2026
Web3 Blockchain C2 Conceals Supply Chain Attacks on Cloud Credentials
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us