惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
aimingoo的专栏
aimingoo的专栏
腾讯CDC
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
Engineering at Meta
Engineering at Meta
博客园_首页
B
Blog RSS Feed
D
Docker
M
MIT News - Artificial intelligence
爱范儿
爱范儿
I
InfoQ

The Last Watchdog

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight | The Last Watchdog News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws | The Last Watchdog News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026 | The Last Watchdog GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it | The Last Watchdog News alert: OpenMatter adds secure routing for OpenAI, Anthropic and Google models | The Last Watchdog LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated | The Last Watchdog News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours | The Last Watchdog MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits | The Last Watchdog NEWS ALERT: Lunar Cyber tracks stolen API keys, ties them to infected employer devices | The Last Watchdog NEWS ALERT: SRA makes SOC AI license-free — customers pay only for the Azure compute they use | The Last Watchdog BLACK HAT FIRESIDE CHAT: How linking SOC alerts cuts noise, reveals attacks taking shape | The Last Watchdog News alert: Airlock Digital IRAP assessment bolsters trust for sensitive Australian deployments | The Last Watchdog News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week | The Last Watchdog MY TAKE: Black Hat 2026 Part 3 — Agentic AI can do the work, but somebody has to prove it | The Last Watchdog MY TAKE: Black Hat 2026 Part 2 — Security shifts to deciding in advance what an AI agent may reach | The Last Watchdog MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing security and operations to merge in the SOC | The Last Watchdog News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures | The Last Watchdog BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure | The Last Watchdog News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries | The Last Watchdog News alert: Mallory links threat intelligence to governed response as exploit timelines shrink | The Last Watchdog News alert: Community voting shapes 2026 Cybersecurity Excellence Awards | The Last Watchdog BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate | The Last Watchdog News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations | The Last Watchdog News alert: Insignary’s on-demand SBOM verification boosts software supply chain security | The Last Watchdog News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions | The Last Watchdog News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI | The Last Watchdog News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk | The Last Watchdog News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks | The Last Watchdog News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks | The Last Watchdog News alert: OpenMatter launches platform to verify AI activity across enterprise systems | The Last Watchdog
News alert: Orchid Security study finds invisible identit...
2026-05-20 · via The Last Watchdog

NEW YORK, May 19, 2026, CyberNewswire—Orchid Security, the company solving identity at its core, today released its Identity Gap: 2026 Snapshot report, revealing that the majority of enterprise identity now exists outside the view of identity and access management systems.

The report found that invisible identity (“identity dark matter�) now outweighs visible identity across enterprise environments, 57% to 43%. Further, 67% of non-human accounts are created directly within the application, unseen and unmanaged by IAM programs.

This finding comes at a critical moment—organizations rapidly deploy AI agents, which in turn accelerates identity exposure. Traditional IAM was built to govern people. It was not built for autonomous systems that inherit credentials, act without human oversight, and often operate within the blind spot that identity dark matter creates.

Additional significant findings:

•70% of enterprise applications contain an excessive number of privileged accounts, dramatically increasing the potential impact of misuse or compromise

•57% of applications bypass centralized identity providers

•40% of accounts are orphaned, remaining available after their users have gone

•36% of all credentials are hardcoded and in clear text within applications

Katmor

“Enterprise identity has crossed a dangerous threshold: the identities we can’t see now outnumber the ones we can,� said Roy Katmor, CEO and co-founder of Orchid Security. “That was already a major security and compliance problem. In the agentic AI era, it becomes an operational crisis. AI agents don’t wait for quarterly reviews. They act in real time, across systems, using whatever access the enterprise makes available to them. If organizations cannot see every identity, understand its authority, and govern its actions, they are not ready to safely scale AI.�

Identity dark matter

The established IAM model for non-human identities has always carried risk: these accounts are typically granted broad, standing access locally (67% of the time, according to analysis of enterprise applications), based on the assumption that their behavior is predetermined and repetitive. A machine, service, or bot that runs the same job on the same schedule poses a risk, but one limited by its code.

However, that all changes with the latest emerging class of actor, Agent AI. While technically nonhuman, Agent AI are far from predetermined and repetitive in their actions. Rather, they are unpredictable and relentless in pursuit of their prompt. Allowing them to run unseen and unmanaged poses a huge risk.

Shadow identity

There is a growing disconnect between formal identity controls and how access actually functions. While many organizations have strengthened corporate IAM systems with a strong stack consisting of a centralized identity directory, strong authentication from an identity provider (IdP), privileged access management (PAM), and increasing identity governance and administration (IGA). Orchid found that these controls are frequently bypassed. Consider that almost 3 out of 4 applications have excessive privileged accounts, more than 1 out of 2 applications allow authentication through local or unmanaged pathways, and 1 out of 3 applications contain credentials stored in clear text, embedded directly in code or configuration files.

All of these contribute to the expanding layer of unmanaged access, or “Identity Dark Matter,� eroding the foundation of identity at its core.

“Organizations have invested heavily in securing the front door, but the research shows identity risk is increasingly concentrated in the side doors: local accounts, unmanaged access paths, hardcoded credentials, and excessive privileges that sit outside formal controls,� Katmor said.

Toxic combinations

Beyond individual exposures, the report identifies what Orchid calls “toxic combinations�—overlapping identity gaps that significantly increase risk.

This includes:

•Orphaned accounts with elevated privileges

•Applications that bypass centralized identity providers while storing credentials in clear text

•Dormant accounts operating without logging or oversight

Individually, these gaps are concerning; together, they create unmonitored access paths that can dramatically increase the potential level of compromise.

Machine-scale exposure

As organizations rapidly deploy AI agents to automate business processes, these identity gaps are not only increasing but are also becoming more visible and more exploitable.

Designed for efficiency, AI agents intuitively identify and utilize the most direct access paths available, including those outside centralized IAM controls, regardless of whether those accounts, credentials, or permissions were intended for their use.

“AI agents discover and exploit identity control gaps and exposures in a way and at a speed we’ve never seen before,� Katmor said. “If there’s a shortcut in your environment, an autonomous system will find it.�

Weak identity foundations.

The findings suggest that many organizations are approaching Agent AI implementation with an incomplete understanding of how access actually works across their environments, often without realizing it. This prevents the necessary risk management that accompanies the advent of AI Agents.

Without first shoring up the foundation of enterprise identity (each application), enterprises expose themselves to increasing cyber, compliance, and operational risks—now at machine scale.

“Identity programs look strong on paper, but most identity activity happens outside them,� said Katmor. “That’s where security, compliance, and AI risks really start to build.�

About the Report: Identity Gap: 2026 Snapshot is based on anonymized telemetry collected from enterprise applications deployed across North America and Europe between April 2025 and March 2026. The data spans industries including financial services, healthcare, retail, manufacturing, and energy, and reflects both managed and unmanaged identity activity across enterprise environments.

Identiverse 2026: Orchid Security will be onsite at Identiverse 2026 at Booth #239 from June 15 – 18. Attendees interested in learning how organizations can safely scale agentic AI while reducing unmanaged identity risk are encouraged to stop by or schedule a meeting with the team onsite.

Orchid Security will also be hosting the following sessions during the event:

When “Lazy� AI Agents Meet Broken Identity Hygiene 

Tuesday, June 16 | 1:15 PM – 1:30 PM | Oceanside E

From Seeing to Knowing: The Identity Observability Frontier

Wednesday, June 17 | 7:15 AM – 8:15 AM | Oceanside E

About Orchid Security: Orchid Security sees straight into the application binary to deliver the industry’s first Identity Control Plane, transforming IAM complexity into clarity, compliance, and control. Its Identity-First Security Orchestration platform continuously discovers enterprise applications, analyzes their native authentication and authorization flows, and accelerates onboarding into governance systems, putting true identity insight in front of security leaders and practitioners, without the months of manual work traditionally required for each task or informational ask. By exposing and remediating the ‘identity dark matter’ hidden across modern environments, Orchid helps enterprises solve identity at its core; reducing risk, lowering operational costs, and achieving compliance at scale. 

Media contact: Chloe Amante, Montner Tech PR, camante@montner.com

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization

May 19th, 2026 | News Alerts | Top Stories