← Back to Feed
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
July 28, 2026 · Dark Reading · Severity: MEDIUM
Ghost credentials, or dormant nonhuman identities such as service accounts, API keys, OAuth tokens, and machine-to-machine certificates, create significant security blind spots in cloud environments. These identities are often provisioned for automation and integrations, then forgotten as teams change and projects evolve, leaving them with excessive privileges that go unmonitored. Attackers increasingly target these stale credentials because they provide persistent access without triggering the alarms that would accompany human account abuse, particularly when the credentials belong to automated workflows that may already appear anomalous.
Key Takeaways
- Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans.
- Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.