Open-Source Secrets Scanner Sift Highlights Credential Sprawl in Microsoft 365, Slack, and Jira

Help Net Security's September 2026 open-source roundup features Sift, a free scanner that hunts leaked credentials in Microsoft 365, Slack, and Jira.

  • Help Net Security's September 2026 open-source roundup features Sift, a free tool that scans Microsoft 365, Slack, and Jira for exposed credentials.
  • School and government IT teams are affected because staff routinely paste API keys, passwords, and tokens into chat, tickets, and documents.
  • Unrotated secrets found in these platforms can give attackers direct access to the accounts and services those credentials protect.

What to do now

  1. Inventory all locations where secrets might be stored, starting with Microsoft 365, Slack, and Jira.
  2. Deploy a secrets scanning tool such as Sift or an equivalent, starting with Microsoft 365 and your most-used collaboration platforms; verify current capabilities, permissions, and data handling with the project's official documentation before enabling it.
  3. Rotate every confirmed exposed credential immediately, and invalidate associated sessions and tokens.
  4. Configure real-time alerts for newly detected secrets, and tune rules to reduce false positives before broad rollout.
  5. Train staff never to paste credentials into chat, tickets, or documents, and integrate scanning into onboarding, offboarding, and change management.

Related items