The Containment Era is here. →Explore

Executive Summary

In July 2026, security researcher Aleksandr Krasnov uncovered a significant security vulnerability involving dormant non-human identities (NHIs) within cloud environments. An AI-enabled workflow agent, inactive for 30 days, unexpectedly initiated API calls at irregular times, prompting an investigation. This led to the discovery of 'ghost credentials'—tokens, agents, and service accounts existing outside traditional trust boundaries yet capable of lateral movement and privilege escalation within systems. Krasnov developed an open-source tool, NHI Hound, to identify and mitigate these hidden trust paths, aiming to enhance organizational security posture.

The incident underscores the escalating risks associated with unmanaged NHIs in increasingly automated and AI-driven infrastructures. As NHIs now outnumber human identities by significant margins, organizations face heightened threats from potential exploitation of these entities. This case highlights the urgent need for robust identity governance frameworks to manage and secure NHIs effectively.

Why This Matters Now

The proliferation of non-human identities in cloud environments presents a growing security challenge, as these entities often operate with excessive privileges and lack proper oversight. This incident highlights the critical need for organizations to implement comprehensive identity governance strategies to mitigate potential exploitation risks associated with NHIs.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

NHIs refer to service accounts, API keys, tokens, and other machine-based credentials that enable automated processes and services to interact within cloud systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to escalate privileges, move laterally, establish command and control channels, and exfiltrate sensitive data, thereby reducing the overall blast radius.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The CNSF would likely constrain unauthorized API calls by enforcing strict identity-based policies, thereby limiting the initial reach of the compromised NHIs.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation would likely limit the ability of compromised NHIs to escalate privileges by enforcing least-privilege access controls.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely restrict lateral movement by monitoring and controlling internal traffic flows, thereby limiting unauthorized access to additional resources.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized command and control channels by providing comprehensive monitoring across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely restrict data exfiltration by controlling and monitoring outbound traffic to unauthorized destinations.

Impact (Mitigations)

While the attack caused operational disruption and data loss, the implemented controls would likely have reduced the overall impact by limiting the attacker's reach and the extent of data exfiltration.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Automated Workflow Operations
  • Identity and Access Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive cloud service configurations and access credentials.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
  • Enhance Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Threat Detection & Anomaly Response systems to identify and mitigate unusual behaviors in real-time.
  • Regularly audit and manage non-human identities to ensure they have appropriate permissions and are not dormant or over-privileged.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image