GitHub AI Can Spot Passwords Hidden in Code Before Developers Push Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


GitHub, with Microsoft Applied Sciences, introduced an AI-powered ModernBERT classifier that detects hidden passwords before code is pushed, expanding push protection beyond known token patterns.

GitHub says it checks batches of possible secrets in under two milliseconds and could more than double the number of secrets prevented.

Announced on October 7, the feature targets a growing gap between software production and credential security. Microsoft reports that one in three GitHub pull requests now involves an AI agent.

As developers and agents create more code, security checks need to keep pace without adding delays or forcing teams to review every change manually.

Traditional secret scanning relies on recognizable patterns, such as a token prefix or a fixed structure. That works for many API keys, but an internal database password may look like an ordinary string. The new classifier reads surrounding code to judge whether a value is likely to be a credential, rather than relying only on its format.

GitHub’s examples show the model identifying password-like values in database URLs, Kubernetes Secret manifests, and Dockerfiles while allowing the placeholder “changeme.”

GitHub AI Can Spot Passwords Hidden

Unlike a chatbot, it does not generate code or text. It classifies candidate secrets, making it suited to checks that must run quickly during a push attempt. The reported speed applies to candidate batches, not the entire repository scan.

Public Pushes, Q2 2024–Q2 2026: Detected Secret Prevalence (source : github )
Public Pushes, Q2 2024–Q2 2026: Detected Secret Prevalence (source: GitHub)

Accuracy matters because a false alarm can interrupt work and weaken trust in future warnings. GitHub says the classifier is more precise than its existing large language model pipelines, while being fast and cheap enough to run within push protection. However, the announcement does not provide a numerical false-positive rate.

GitHub reviewed nine quarters from Q2 2024 through Q2 2026. Screened public pushes rose 2.84 times, while pushes containing supported credentials grew 2.59 times.

The company found no statistically detectable trend in the share of pushes containing secrets. Meanwhile, developers’ overrides of push-protection blocks fell from 6.63% to 3.93%. These findings suggest rising activity, rather than growing carelessness, is driving the workload.

Across the broader secret types GitHub detects, push protection stops about 30% before they enter repository history. The remaining 70% are found afterward.

Manual revocation takes around 40 days on average, with roughly one in five secrets taking more than 90 days. Related CybersecurityNews coverage of exposed GitHub credentials explains why detection alone does not close access.

AI-based push protection is in private preview, with availability planned later in October for GitHub Secret Protection customers on Enterprise Cloud and GitHub Team plans. It will consume AI credits. Existing organizations using AI secret detection will be upgraded automatically; post-push alerts will remain included at no added cost.

GitHub plans public-preview alerts in Enterprise Server 3.23, including air-gapped environments, and checks through Copilot CLI and Copilot App’s /security-review command.

Prevention still cannot repair earlier leaks. GitHub’s secret scanning partner program lets providers receive exposure reports and revoke credentials. For security teams, blocking new leaks and removing access from exposed secrets remain separate, necessary tasks.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post GitHub AI Can Spot Passwords Hidden in Code Before Developers Push Them appeared first on Cyber Security News.