<?xml version="1.0" encoding="UTF-8" ?> <?xml-stylesheet type="text/xsl" href="rss.xsl"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"> <channel> <title>Kingfisher</title><description>Open source secret scanner with live validation. 950 detection rules, blast radius mapping, credential revocation, and a browser-based report viewer that also imports Gitleaks and TruffleHog output. Built in Rust by MongoDB.</description><link>https://mongodb.github.io/kingfisher/</link><atom:link href="https://mongodb.github.io/kingfisher/feed_rss_updated.xml" rel="self" type="application/rss+xml" /> <managingEditor>MongoDB</managingEditor><docs>https://github.com/mongodb/kingfisher</docs><language>en</language> <pubDate>Fri, 22 May 2026 22:37:58 -0000</pubDate> <lastBuildDate>Fri, 22 May 2026 22:37:58 -0000</lastBuildDate> <ttl>1440</ttl> <generator>MkDocs RSS plugin - v1.19.0</generator> <image> <url>None</url> <title>Kingfisher</title> <link>https://mongodb.github.io/kingfisher/</link> </image> <item> <title>Beyond Detection: Live Validation, Blast Radius, and One-Command Revocation</title> <category>Features</category> <category>blast-radius</category> <category>revocation</category> <category>secret-scanning</category> <category>validation</category> <description>Detection alone is noise. Kingfisher answers the three questions that actually matter when a secret leaks — is it live, what does it reach, and can we revoke it now — across AWS, GCP, GitHub, GitLab, Slack, and dozens of other providers. </description> <link>https://mongodb.github.io/kingfisher/blog/2026/04/28/beyond-detection-live-validation-blast-radius-and-one-command-revocation/</link> <pubDate>Fri, 22 May 2026 22:37:38 +0000</pubDate> <source url="https://mongodb.github.io/kingfisher/feed_rss_updated.xml">Kingfisher</source><guid isPermaLink="true">https://mongodb.github.io/kingfisher/blog/2026/04/28/beyond-detection-live-validation-blast-radius-and-one-command-revocation/</guid> </item> <item> <title>Scanning an Entire GitHub Organization for Leaked Secrets</title> <category>Tutorials</category> <category>github</category> <category>secret-scanning</category> <category>tutorial</category> <category>validation</category> <description>Step-by-step guide to scanning every repository in a GitHub organization for leaked credentials with Kingfisher — including history, issues, wikis, and gists — and validating which secrets are still live. </description> <link>https://mongodb.github.io/kingfisher/blog/2026/04/28/scanning-an-entire-github-organization-for-leaked-secrets/</link> <pubDate>Fri, 22 May 2026 22:37:38 +0000</pubDate> <source url="https://mongodb.github.io/kingfisher/feed_rss_updated.xml">Kingfisher</source><guid isPermaLink="true">https://mongodb.github.io/kingfisher/blog/2026/04/28/scanning-an-entire-github-organization-for-leaked-secrets/</guid> </item> <item> <title>Scanning Postman for Leaked Secrets — Including the Ones the UI Hides</title> <category>Features</category> <category>integrations</category> <category>postman</category> <category>secret-scanning</category> <category>validation</category> <description>Postman workspaces are a quietly underrated leak surface. Kingfisher now scans collections, environments, mocks, and monitors directly via the Postman API — and reads the plaintext of &#34;secret&#34;-typed environment variables that the Postman UI masks but the API does not. </description> <link>https://mongodb.github.io/kingfisher/blog/2026/04/29/scanning-postman-for-leaked-secrets--including-the-ones-the-ui-hides/</link> <pubDate>Fri, 22 May 2026 22:37:38 +0000</pubDate> <source url="https://mongodb.github.io/kingfisher/feed_rss_updated.xml">Kingfisher</source><guid isPermaLink="true">https://mongodb.github.io/kingfisher/blog/2026/04/29/scanning-postman-for-leaked-secrets--including-the-ones-the-ui-hides/</guid> </item> <item> <title>Real-time Secret Alerts: Webhooks for Slack, Teams, Discord, Mattermost, and Google Chat</title> <category>Features</category> <category>alerts</category> <category>discord</category> <category>google-chat</category> <category>integrations</category> <category>mattermost</category> <category>slack</category> <category>teams</category> <category>webhooks</category> <description>Kingfisher now POSTs scan results straight to your team&#39;s chat the moment a scan completes — Slack, Microsoft Teams, Discord, Mattermost, Google Chat, or any HTTPS endpoint. With per-finding fingerprints, a pivot link to the full report, and an auto-summary mode that keeps high-volume scans from spamming the channel. </description> <link>https://mongodb.github.io/kingfisher/blog/2026/05/04/real-time-secret-alerts-webhooks-for-slack-teams-discord-mattermost-and-google-chat/</link> <pubDate>Fri, 22 May 2026 22:37:38 +0000</pubDate> <source url="https://mongodb.github.io/kingfisher/feed_rss_updated.xml">Kingfisher</source><guid isPermaLink="true">https://mongodb.github.io/kingfisher/blog/2026/05/04/real-time-secret-alerts-webhooks-for-slack-teams-discord-mattermost-and-google-chat/</guid> </item> </channel> </rss>