Passwork Blog

Latest May 28, 2026
Passwork has been named a Top Performer Spring 2026 by SourceForge, ranking in the top 10% of 100,000+ solutions. The...

Passwork wins Top Performer Spring 2026 on SourceForge

Passwork has been named a Top Performer Spring 2026 by SourceForge, ranking in the top 10% of 100,000+ solutions. The badge is based entirely on verified reviews — 4.8 stars overall, with a perfect 5.0 for support.

Passwork wins Top Performer Spring 2026 on SourceForge
May 20, 2026 16 min read
Hardcoded secrets are credentials written directly into code instead of injected at runtime. They survive in Git...

What are hardcoded secrets and why are they so risky?

Hardcoded secrets are credentials written directly into code instead of injected at runtime. They survive in Git history, CI/CD logs, and forks long after the "fix" commit. This guide covers how they spread, how to detect them, and how to eliminate them.

What are hardcoded secrets and why are they so risky?
May 20, 2026 22 min read
Secret rotation fails when it's treated as a scheduled task rather than a lifecycle. This guide covers all seven stages...

Secrets rotation lifecycle: From creation to revocation

Secret rotation fails when it's treated as a scheduled task rather than a lifecycle. This guide covers all seven stages — from creation and ownership to safe rotation, emergency revocation, and audit evidence.

Secrets rotation lifecycle: From creation to revocation
May 15, 2026 27 min read
28.65 million secrets leaked on public GitHub in 2025. AI is accelerating the problem. Internal repos are 6× more...

The state of secrets sprawl in 2026: Key findings from GitGuardian's report

28.65 million secrets leaked on public GitHub in 2025. AI is accelerating the problem. Internal repos are 6× more exposed than public ones. And 64% of secrets from 2022 are still valid today. Here is what the data means for your security posture.

The state of secrets sprawl in 2026: Key findings from GitGuardian's report
May 14, 2026 20 min read
APT28 hijacked 18,000 routers to steal OAuth tokens. Storm-2372 bypassed MFA without touching a password. 28.6 million...

Credential threats in April 2026: Supply chain attacks and 28 million exposed secrets

APT28 hijacked 18,000 routers to steal OAuth tokens. Storm-2372 bypassed MFA without touching a password. 28.6 million secrets leaked on GitHub. April 2026's biggest incidents — and what they have in common.

Credential threats in April 2026: Supply chain attacks and 28 million exposed secrets
Apr 28, 2026 18 min read
Why breach your network when attackers can compromise a trusted dependency with millions of downloads and slip silently...

Inside real supply chain attacks: Bitwarden CLI, Axios, and Vercel

Why breach your network when attackers can compromise a trusted dependency with millions of downloads and slip silently into thousands of organizations at once? Three 2026 campaigns prove supply chain attacks are no longer isolated incidents.

Inside real supply chain attacks: Bitwarden CLI, Axios, and Vercel
Apr 19, 2026 21 min read
84% of in-scope organizations admit they're not ready. Belgium set the first conformity assessment deadline on April...

NIS2 latest news: What changed in 2026 and what it means for EU businesses

84% of in-scope organizations admit they're not ready. Belgium set the first conformity assessment deadline on April 18, 2026. The Netherlands is days away from enforcement. Here's where the regulatory wave stands and what IT leaders need to act on now.

NIS2 latest news: What changed in 2026 and what it means for EU businesses
Apr 11, 2026 18 min read
GPU clusters, AI-assisted wordlists, botnets of 2.8M devices. Brute force has scaled. This guide covers six attack...

Brute force attacks in 2026: What they are and how to stop them

GPU clusters, AI-assisted wordlists, botnets of 2.8M devices. Brute force has scaled. This guide covers six attack variants, real-world cases from 2025, and a layered defense strategy your team can implement today.

Brute force attacks in 2026: What they are and how to stop them
Apr 10, 2026 12 min read
A forgotten password costs $70. A breach costs $4.44 million. Both start the same way — credentials shared over Slack,...

Password chaos: Why it's a business problem and how to fix it

A forgotten password costs $70. A breach costs $4.44 million. Both start the same way — credentials shared over Slack, stored in spreadsheets, never rotated. Here's what password chaos actually costs and how to eliminate it.

Password chaos: Why it's a business problem and how to fix it
Apr 9, 2026 10 min read
NIS2 Article 21(2)(j) mandates MFA "where appropriate" — not passwordless by default. Learn what ENISA guidance...

Is NIS2 passwordless authentication required for compliance?

NIS2 Article 21(2)(j) mandates MFA "where appropriate" — not passwordless by default. Learn what ENISA guidance actually requires, how auditors evaluate your implementation, and how to build a defensible hybrid compliance posture for 2026.

Is NIS2 passwordless authentication required for compliance?