Attackers can compromise developer environments through classic, easily exploitable bugs with minimal user interaction and steal all stored secrets and source code.
AI agents require dynamic identities, short-lived secrets, and gradually reduced privileges instead of static access rights to ensure security and auditability.
Centralized secrets management with audit logs and automated rotation is becoming mandatory to meet regulatory requirements and reduce attack surfaces in cloud and container environments.
Leaked GitHub tokens at Novo Nordisk demonstrate that secrets management must be properly addressed as an identity problem, not merely as a tooling challenge.