Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Summary
Security researcher Aleksandr Krasnov has identified a new cloud security risk: 'ghost credentials' or dormant non-human identities. These hidden identities can create significant security blind spots within cloud systems. To address this, Krasnov has released an open-source tool called NHI Hound to help detect and manage these trust paths.
IFF Assessment
The discovery of 'ghost credentials' and the potential for hidden identity risks exposes new attack vectors for threat actors, making it harder for defenders to secure cloud environments.
Defender Context
Defenders should be aware of the risks posed by dormant non-human identities in cloud environments, as these can be exploited by attackers to gain unauthorized access or escalate privileges. Implementing regular audits and utilizing tools like NHI Hound to identify and revoke unnecessary or forgotten credentials is crucial for mitigating this threat.