Hemanth Gorijala
Hemanth Gorijala is an application security professional and penetration tester with 13 years of experience in a global Fortune 500 environment. He conducts web application security assessments and reviews vulnerability reports in enterprise bug bounty programs. The exploitation chains in this talk are drawn from his own authorized assessments. He built SecretSifter to close the runtime security gap.
Session
A bug bounty researcher found Azure credentials in a JavaScript file and called it done. I kept going — four Azure AD credentials, enough to authenticate as the application itself. Full account takeover. The organization had GitLeaks in CI/CD and static secret scanning. The credentials were still live. Shift-left tools scan what you commit. They do not scan what you serve. Once a secret reaches production, it disappears from every scanner's view.