CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3390

As cited

Copy frozen at (site build).

cloud saas

Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

Security researcher Aleksandr Krasnov has identified risks posed by dormant non-human identities (NHI) that can remain hidden in cloud systems and create security blind spots. The researcher released NHI Hound, an open source tool designed to discover and map trust paths associated with these identities. The research highlights how inactive service accounts and other non-human entities can become overlooked vectors for unauthorized access.

Why it matters: Cloud practitioners need to audit non-human identities across their infrastructure today, as dormant accounts represent unmonitored attack surface that existing tools may not detect.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary