Open-Source Secrets Scanner Sift Highlights Credential Sprawl in Microsoft 365, Slack, and Jira
Help Net Security's September 2026 open-source roundup features Sift, a free scanner that hunts leaked credentials in Microsoft 365, Slack, and Jira.
- Help Net Security's September 2026 open-source roundup features Sift, a free tool that scans Microsoft 365, Slack, and Jira for exposed credentials.
- School and government IT teams are affected because staff routinely paste API keys, passwords, and tokens into chat, tickets, and documents.
- Unrotated secrets found in these platforms can give attackers direct access to the accounts and services those credentials protect.
What to do now
- Inventory all locations where secrets might be stored, starting with Microsoft 365, Slack, and Jira.
- Deploy a secrets scanning tool such as Sift or an equivalent, starting with Microsoft 365 and your most-used collaboration platforms; verify current capabilities, permissions, and data handling with the project's official documentation before enabling it.
- Rotate every confirmed exposed credential immediately, and invalidate associated sessions and tokens.
- Configure real-time alerts for newly detected secrets, and tune rules to reduce false positives before broad rollout.
- Train staff never to paste credentials into chat, tickets, or documents, and integrate scanning into onboarding, offboarding, and change management.