Thursday, July 30, 2026
NewsezeNews with Rewards · Earn while you read
+5 credits / query
cyber

Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

Newseze Wire·Tue, Jul 28, 9:33 PMWire: Dark Reading
Open original source Read full story (in-site)
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.

Sourcing & attribution. Newseze provides AI-curated summaries, narrative framing, and editorial analysis. The underlying reporting was contributed by Dark Reading; tap “Open original source” above to read their full reporting and support the contributing newsroom directly.

Newseze Analysis420 words · original commentary
# Ghost Credentials Expose Cloud Systems to Hidden Identity Risks Cloud infrastructure relies on machine-to-machine authentication through non-human identities (NHIs)—service accounts, API keys, and role-based credentials that enable automated systems to communicate and perform tasks. A security researcher has identified a significant oversight: many organizations lose track of these dormant identities over time, creating what amounts to unlocked doors in their digital architecture. The problem isn't theoretical. Abandoned credentials can persist across infrastructure redesigns, departures, and system migrations, leaving pathways that attackers could exploit if discovered. The researcher has released an open-source scanning tool designed to help organizations inventory these hidden trust relationships before they become security liabilities. The significance of this finding lies in the operational reality of modern cloud environments. As systems scale and teams evolve, service accounts and API credentials are often created for temporary integrations or deprecated services—then forgotten. Unlike human accounts that trigger offboarding procedures, these non-human identities frequently escape regular security audits. An attacker gaining access to a forgotten service account could potentially move laterally through the network or escalate privileges without triggering the monitoring systems designed to catch anomalous human behavior. The research highlights what amounts to a gap between cloud security theory and practice: many organizations have governance frameworks for user access but lack equivalent rigor for machine identities. The release of NHI Hound—an open-source tool for mapping these hidden trust relationships—offers practical value for security teams. By identifying dormant credentials and the paths they can access, organizations gain visibility into attack surfaces they likely didn't know existed. This reflects a broader industry maturation: security increasingly requires not just better defenses, but better inventory. The tool's availability as open-source rather than commercial software signals that the security community views this as a foundational need rather than a premium service. The quality of this finding depends on real-world adoption and whether the tool accurately identifies credential relationships across diverse cloud platforms, but the underlying premise—that forgotten machine identities represent genuine risk—aligns with established security principles. **Worth knowing:** The research underscores a persistent gap between cloud security aspirations and day-to-day operational reality. Organizations optimizing for speed and flexibility during cloud migration often deprioritize credential housekeeping. This isn't usually negligence; it's the accumulation of small decisions during rapid scaling. As cloud adoption matures, the unsexy work of identity inventory and hygiene has become as critical as encryption or network segmentation. Teams responsible for cloud security should treat machine identity lifecycle management—creation, monitoring, and retirement—with the same rigor applied to user access control. **Reporting:** Dark Reading.
Ask Us · Any Story, Any AnswerBe the first to ask

Newseze's algorithm reads the story and answers your question — calmly, factually, with source attribution. No comments, no flame wars — just answers.

No questions yet. Be the first.

Answers reflect Newseze's editorial framework applied under fair use (17 U.S.C. § 107). Not financial, legal, medical, or tax advice. Hate speech and racial slurs are blocked.

Related stories

Iran-Linked Hackers Target U.S. Critical Infrastructure Controllers, CISA Warns
CYBERTrending Righttrust 100
Iran-Linked Hackers Target U.S. Critical Infrastructure Controllers, CISA Warns

Why it mattersActive exploitation of programmable logic controllers in power, water, and industrial systems poses direct risk to national security and civilian infrastructure; CISA alert enables defenders to identify and patch vulnera…

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure    CISA (.gov)

ChellaBy Chella·Jul 22
WireCISA Alerts via Google News
Full Analysis Comment PostRead →
Southeast Asian Criminal Networks Expand Global Reach, Exploit Victims Across 80 Countries
CYBERtrust 82
Southeast Asian Criminal Networks Expand Global Reach, Exploit Victims Across 80 Countries

Why it mattersOrganized crime syndicates based in Southeast Asia have grown into multinational enterprises trafficking people and selling illicit services worldwide, representing a $88 billion annual drain on the region's economy and …

The groups move from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alo…

ChellaBy Chella·1h ago
WireDark Reading
Full Analysis Comment PostRead →
Chinese-Linked 'Flying Eagle' Malware Service Spreads Financial Theft Tools Across Asia
CYBERtrust 77
Chinese-Linked 'Flying Eagle' Malware Service Spreads Financial Theft Tools Across Asia

Why it mattersA sophisticated mobile remote access trojan builder is enabling multiple criminal groups to steal from bank customers across the region, forcing financial institutions and device manufacturers to accelerate threat detect…

A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.

MarcusBy Marcus·1h ago
WireDark Reading
Full Analysis Comment PostRead →
FBI Dismantles NetNut Proxy Network Tied to 2 Million Compromised Devices
CYBERtrust 91
FBI Dismantles NetNut Proxy Network Tied to 2 Million Compromised Devices

Why it mattersThe seizure disrupts a major infrastructure used for credential theft and fraud while testing law enforcement's ability to pursue cyber criminals operating through publicly traded companies and international jurisdiction…

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residenti…

ChellaBy Chella·Jul 2
WireKrebs on Security
Full Analysis Comment PostRead →