BSides San Antonio 2026 June 13 at St. Mary's University A bug bounty researcher found Azure credentials in a JavaScript file and called it done. I kept going — four Azure AD credentials, enough to authenticate as the application itself. Full account takeover. The organization had GitLeaks in CI/CD and static secret scanning. The credentials were still live. Shift-left tools scan what you commit. They do not scan what you serve. Once a secret reaches production, it disappears from every scanner's view.