Funding/M&A

HashiCorp Buys BluBracket for Secrets Scanning Tech

HashiCorp acquires BluBracket secrets-scanning technology to help businesses block accidental leaks and fight secret sprawl.

HashiCorp acquires BluBracket secrets-scanning technology to help businesses block accidental leaks and fight secret sprawl.

Cloud infrastructure software firm HashiCorp on Tuesday announced a deal to acquire BluBracket, an early stage startup building technology to help businesses scan for secrets hidden in source code.

Financial terms of the acquisition were not released. 

BluBracket, based in Silicon Valley, raised $18.5 million in venture capital funding from Evolution Equity Partners, Unusual Ventures, Point72 Ventures, SignalFire and Firebolt Ventures. 

In a statement announcing the acquisition, HashiCorp said BluBracket’s code scanning will complement HashiCorp Vault’s secrets management to help prevent accidental leaks and fight secrets sprawl that haunt the software supply chain.

BluBracket sells technology to help defenders easily scan, identify, and address secrets hidden in their source code, development environments, internal websites, chat services, ticketing systems, and other locations.  

Related: ‘Secrets Sprawl’ Haunts Software Supply Chain Security

Advertisement. Scroll to continue reading.

Related: HashiCorp Among Codecov Supply Chain Hack Victims

Related: Software Supply Chain: The Golden Container Ship

Related: Akeyless Raises $65 Million for Secrets Management Tech

Related Content

Supply Chain Security

Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.

Application Security

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.

Application Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.

Cybersecurity Funding

The British firm has built a collaborative platform to help organizations address supply chain security risks.

Supply Chain Security

By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed.

Cybersecurity Funding

The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion.

Supply Chain Security

New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.

Supply Chain Security

Rather than scanning code alone, Build Application Firewalls inspect runtime behavior inside the software build pipeline.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version