- What: Security researcher reveals hidden identity risks from dormant non-human identities.
- Impact: Organizations using cloud systems should be aware of potential blind spots.
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources СLOUD SECURITY IDENTITY & ACCESS MANAGEMENT SECURITY ENDPOINT SECURITY Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Ghost Credentials Expose Cloud Systems to Hidden Identity Risks Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths. Jeffrey Schwartz,Contributing Writer July 28, 2026 3 Min Read SOURCE: IGOR STEVANOVIC VIA ALAMY STOCK PHOTO A seemingly minor insider incident last year involving a small, isolated cloud account turned out to be a harbinger of a potentially larger identity problem. When an AI‑enabled workflow agent that had been idle for 30 days suddenly woke up and began firing off API calls at unusual times, it triggered an anomaly investigation. During the course of the investigation, Aleksandr Krasnov, a distinguished security architect at Ducker Tech Consulting, discovered a mesh of "ghost credentials" and non‑human identities — tokens, agents, and service accounts that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges to access systems. Krasnov declined to describe specifics of the incident, but he says it exposed a much larger blind spot: organizations have lost track of what and who they trust in heavily automated, AI‑based environments. LOADING... Related:CSA Launches CSAI Foundation for AI Security By tracing the abused workflow agent and its dormant permissions, Krasnov saw just how many non‑human identities quietly sit outside conventional trust models, and even more concerning, how many can escalate to gain root or administrator status. Krasnov plans to outline a red-team methodology for turning a single leaked key into a full cloud compromise, or abusing chained trust relationships to pivot into identity providers such as Okta, as part an online session at the end of Black Hat USA 2026. An attacker can choose between spending "two weeks" creating a phishing campaign, or "five minutes" hunting for exposed tokens, Krasnov says. The likely bet is on the five‑minute path using ghost credentials, he notes. Krasnov will then pivot to a blue‑team perspective on rebuilding a "source of truth" for non‑human trust, and plans to release NHI Hound, an open‑source tool he developed that ingests identity data from providers such as Okta, GitHub, and cloud IAM platforms. NHI Hound exposes hidden trust links between human and non‑human accounts. He simulates worst‑case abuse paths so defenders can see which dormant credentials actually lead into production environments or identity‑provider admin roles. The open‑source tool also collects an inventory of an organization's full catalog of non‑human identities and human identities, classifies them by trust‑severity levels, and suggests remediation steps. Krasnov describes "critical" conditions as those where low‑trust identities can effectively perform the same actions as super‑admin accounts because of implicit or inferred trust relationships that an organization never explicitly defined. Related:The Tug-of-War Over Firewall Backlogs in the AI-Driven Development Era Although Krasnov hasn't yet worked with organizations to create formal proof‑of‑concept pilots of NHI Hound, informal testing from small-to-mid-size companies (up to 2,000 employees) has shown "some very good results and really good feedback," he says. Smaller, fast‑moving organizations can realistically take 6 to 9 months to clean up their non‑human identity trust graph using this tool, Krasnov says. That won't be the case for larger enterprises, because the greater number of identities to manage makes the problem more severe and difficult to address. According to Krasnov's research, one developer may have up to 244 non‑human identities, meaning that when an organization grows beyond roughly 2,000 employees, "the whole graph becomes super, super messy," making it difficult to track identities. As a result, he notes, big organizations may find the output "too much mess and too much noise," with so many critical trust issues that it would be difficult to know where to start. Looking forward, Krasnov says he would like to make NHI Hound more suitable for larger organizations by enabling better visualization, more usable graphs, and more "pretty output" to handle larger identity graphs more effectively — presuming there is uptake for the current iteration and user feedback on the tool. Krasnov also hints that he is working toward a broader rethinking of identity management and trust boundaries. Related:'Encrypt It Already' Campaign Pushes Big Tech to Prioritize E2E Encryption Black Hat USA AUG 1, 2026 TO AUG 6, 2026 | MANDALAY BAY CONVENTION CENTER, LAS VEGAS, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass. GET YOUR PASS Read more about: Black Hat News About the Author Jeffrey Schwartz Contributing Writer Jeffrey Schwartz is a journalist who has covered information security and all forms of business and enterprise IT, including client computing, data center and cloud infrastructure, and application development for more than 30 years. Jeff is a regular contributor to Channel Futures. Previously, he was editor-in-chief of Redmond magazine and contributed to its sister titles Redmond Channel Partner, Application Development Trends, and Virtualization Review. Earlier, he held editorial roles with CommunicationsWeek, InternetWeek, and VARBusiness. Jeff is based in the New York City suburb of Long Island. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like СLOUD SECURITY APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials by Elizabeth Montalbano APR 13, 2026 СLOUD SECURITY The Cloud Edge Is the New Attack Surface by Robert Lemos SEP 17, 2025 СLOUD SECURITY Phishing Empire Runs Undetected on Google, Cloudflare by Elizabeth Montalbano SEP 04, 2025 СLOUD SECURITY DARPA: Closing the Open Source Security Gap by Alexander Culafi AUG 21, 2025 Edge Picks APPLICATION SECURITY AI Agents in Browsers Light on Cybersecurity, Bypass Controls CYBER RISK Browser Extensions Pose Heightened, but Manageable, Security Risks CYBERSECURITY OPERATIONS Video Convos: Agentic AI, Apple, EV Chargers; Cybersecurity Peril Abounds ENDPOINT SECURITY Extension Poisoning Campaign Highlights Gaps in Browser Security Latest Articles in The Edge CYBERSECURITY OPERATIONS Former Citigroup CISO Blauner on What Makes A Great Security Leader JUL 28, 2026 ENDPOINT SECURITY Why Resetting Passwords No Longer Stops Attackers JUL 27, 2026 CYBERSECURITY OPERATIONS CISOs vs. Boards: Myth or Misunderstanding? JUL 24, 2026 CYBERSECURITY OPERATIONS Agentic AI: Taming the Unpredictable JUL 16, 2026 Read More The Edge Want more Dark Reading stories in your Google search results? LOADING... BLACK HAT ASIA | MARINA BAY SANDS, SINGAPORE Experience cutting-edge cybersecurity insights in this four-day event. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices