Leaking Secrets in the Age of AI: How AI Adoption is Creating New Attack Vectors @OWASPGLOBAL
Leaking Secrets in the Age of AI: How AI Adoption is Creating New Attack Vectors  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/5b/LeakingSecretsInTheAgeOfAI.pdf

In a rush to adopt and experiment with AI, corners are getting cut. This is evident from incidents of resource abuses (attackers running adult bots for profit), unsafe 3rd-party model executions, and a variety of model escape vulnerabilities.
A major, underexplored side effect, however, is the leakage of AI secrets in public repositories. Despite the general awareness about exposed secrets in code, finding a valid secret remains shockingly easy, you just need to know where to look. High-privilege secrets with enterprise-wide impact are out in the wild, waiting to be found.

This talk presents a novel methodology for identifying “juicy” (high-value and high-probability) targets for secret hunting using BigQuery / githubarchive, GitHub API, and automated secret scanning tools. Based on this methodology, I will present findings from an intensive month-long secret scanning campaign across thousands of repositories, revealing hundreds of validated secrets from over 40 organizations—including multiple Fortune 100 companies. We’ll analyze the results, showing how AI-related secrets constitute a disproportional majority, and what new leakage patterns are emerging from this Age of AI.

The presentation concludes with actionable mitigation strategies, serving as a wake-up call for AI and data science communities to urgently improve their security practices.

Shay Berkovich
Wiz
Threat Research
Tel Aviv
twitter.com/sshaybbc
linkedin.com/in/shay-berkovich-0a09975

Shay is part of the Threat Research team in Wiz working on various aspects of container and more recently code and CICD security. He worked previously at BlackBerry, Symantec and BlueCoat on a range of security products (CWPP, WAF, SWG) doing applied security research and security architecture. Shay holds a Masters’ degree from UW with (somewhat unexpected) thesis in runtime verification and has delivered several talks in academic and industrial security conferences.
linkedin.com/in/shay-berkovich-0a09975
wiz.io/blog (company)
wiz.io/authors/shay-berkovich (blog)

Managed by the OWASP® Foundation
owasp.org
Leaking Secrets in the Age of AI: How AI Adoption is Creating New Attack VectorsBuilding Security Into Developer Velocity: How We Made Entra Identity Compliance Invisible track 1Keynote by Adam Shostack: Stop Trying to Manage RiskOWASP Board of Directors - July 2026 Public Board MeetingNo Fate But What We Make: Doing Intrusion PredictionCycloneDX 2.0 Preview: Evolving BOM Architecture for Broader ApplicabilityGuardrails First: Building AI Agents That Won’t Leak Your Secrets - Track 2Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan WorcelSelf-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving ThreatsAMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary Vulnerability
OWASP Foundation |

Leaking Secrets in the Age of AI: How AI Adoption is Creating New Attack Vectors

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER