This page may contain stale information. Last updated: 2026-08-14

Definition

Secret rotation failure is when an organization claims credentials exposed in a breach were rotated, but stolen secrets remain valid and usable months later.

Key Points

  • Demonstrated Aug 2026 by kevin-beaumont against a major US tech company after litellm March compromise
  • Damage window ≠ package exposure window (40 minutes on pypi-malware vs months until full rotation)
  • Related to credential-reuse and incomplete revocation (e.g., Trivy automation token lapse)
  • Remediation: assume all CI-accessible secrets compromised; rotate broadly; verify with testing policy

Sources