The bottom line: Unmanaged machine identities in cloud systems create attack paths that traditional IAM controls overlook.
Security researcher Aleksandr Krasnov has demonstrated that inactive non-human identities (NHI) create security blind spots in cloud systems. With the new open-source tool NHI Hound, he provides a means to identify such orphaned trust paths.
Non-human identities such as service accounts, API keys, and certificates are routinely used in cloud architectures for authentication and authorization. However, many of these identities are no longer maintained during their lifecycle but remain with active permissions — a phenomenon known as “ghost credentials.”
The security risk lies in the fact that these orphaned identities can lead to unmonitored trust paths. Attackers exploit such weaknesses to navigate laterally through cloud systems or escalate privileges. For CISOs, this is particularly problematic because traditional identity and access management (IAM) often overlooks such inactive but authorized accounts.
With NHI Hound, Krasnov offers an open-source tool designed to help organizations identify dormant non-human identities and their trust relationships in cloud environments. The tool aims to make these security gaps visible and thereby become part of comprehensive machine identity hygiene.
Source: www.darkreading.com · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification via Lumi News Pipeline v1.7.3.