This page may contain stale information. Last updated: 2026-08-14
Definition
Secret rotation failure is when an organization claims credentials exposed in a breach were rotated, but stolen secrets remain valid and usable months later.
Key Points
- Demonstrated Aug 2026 by kevin-beaumont against a major US tech company after litellm March compromise
- Damage window ≠ package exposure window (40 minutes on pypi-malware vs months until full rotation)
- Related to credential-reuse and incomplete revocation (e.g., Trivy automation token lapse)
- Remediation: assume all CI-accessible secrets compromised; rotate broadly; verify with testing policy