惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Help Net Security
Help Net Security
Recent Announcements
Recent Announcements
A
About on SuperTechFans
N
News and Events Feed by Topic
I
Intezer
B
Blog
GbyAI
GbyAI
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Project Zero
Project Zero
T
The Blog of Author Tim Ferriss
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
T
Troy Hunt's Blog
TaoSecurity Blog
TaoSecurity Blog
IT之家
IT之家
MyScale Blog
MyScale Blog
The Register - Security
The Register - Security
Cyberwarzone
Cyberwarzone
Y
Y Combinator Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
酷 壳 – CoolShell
酷 壳 – CoolShell
Stack Overflow Blog
Stack Overflow Blog
P
Privacy & Cybersecurity Law Blog
S
Secure Thoughts
MongoDB | Blog
MongoDB | Blog
N
Netflix TechBlog - Medium
Hacker News - Newest:
Hacker News - Newest: "LLM"
G
Google Developers Blog
罗磊的独立博客
博客园 - 聂微东
G
GRAHAM CLULEY
AWS News Blog
AWS News Blog
Google Online Security Blog
Google Online Security Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
H
Hacker News: Front Page
C
Check Point Blog
L
Lohrmann on Cybersecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Spread Privacy
Spread Privacy
O
OpenAI News
T
Tor Project blog
P
Privacy International News Feed
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Attack and Defense Labs
Attack and Defense Labs
L
LINUX DO - 最新话题
Forbes - Security
Forbes - Security
云风的 BLOG
云风的 BLOG
C
Cisco Blogs
S
Securelist
博客园_首页

WhatIs

Strategic IT outlook: Tech conferences and events calendar | TechTarget 8 AI use cases in manufacturing Enterprises are making an AI native transformation Zero trust in the IT ops stack: Securing hybrid workloads How algorithmic value sets enhance clinical decision-making Top methods for collecting customer feedback Build a data governance team that delivers results How to calculate the total cost of ownership of ERP software Communities call for transparency in AI data center deals Scalable IT infrastructure: Balancing speed with stability How health systems are tackling 'Kill the Clipboard' obstacles Understanding the science behind AI-based hiring assessments Tape's strategic role in modern data protection How to choose an HR software system in 2026: A complete guide The UC stack gets the policy job Top zero-trust use cases in the enterprise 13 top IT infrastructure conferences in 2026 SNMP vs. CMIP: What's the difference? 3 essential network analytics use cases AI Security Risks Force CIOs to Rethink Strategy Red Hat Summit 2026 news and conference guide | TechTarget What is HR technology (human resources tech)? Understand, optimize and track customer journey touchpoints Should IT use Apple Business Manager without MDM? Build and organize an effective machine learning team The storage modernization imperative in a fast-changing IT landscape Procurement automation use cases for CSCOs to consider 3 steps for health system leaders to drive patient safety culture What is DevOps? Meaning, methodology and guide Enterprises Face New Storage Bottlenecks as AI Grows A guide to Intune Suite licensing for endpoint management Epic controls 42% of the US EHR market. Does that help or hurt interoperability? SAP Sapphire 2026 news, trends and analysis | TechTarget How to develop a data governance strategy: 7 key steps 12 generative AI tools for marketing and sales teams Top 9 smart contract platforms to consider in 2026 Top 8 e-signature software providers for 2026 Rise with SAP vs. S/4HANA Cloud: What are the differences? How businesses use KPIs to measure AI's performance 5 clues your network has shadow AI How do digital signatures work? Collaboration security and governance must be proactive Compare SAP greenfield vs. brownfield approach for S/4HANA Merck, Home Depot tap Gemini Enterprise for AI agent development Rural challenges may dampen digital healthcare's potential Build an ethical AI framework: 12 top resources The great workload reshuffle: Choices for AI and analytics How to remove a device from Intune enrollment Cisco unveils quantum network advancements 3 BYOD security risks and how to prevent them 10 of the top carbon accounting software 8 trends powering machine learning's dynamic new roles Network engineers must take the lead to push DDI to the cloud How does Microsoft 365 Copilot pricing and licensing work? ONC highlights behavioral health EHR adoption trends, data exchange barriers LLMs struggle with clinical reasoning, study finds Democratizing AI in business: The good, bad and ugly What can organizations do to address BYOD privacy concerns? Fix the service path before you optimize it with AI How AI reshapes upselling in customer experience platforms When collaboration starts becoming operational drag Balancing health AI management with growing vendor sprawl Career cure for AI phobia: Be a beekeeper, not a worker bee 16 top applicant tracking systems for 2026 How a rural community hospital deploys AI to detect heart disease 8 examples of document version control Guide to 30+ sustainability certifications for professionals AI agents are only as smart as the data that feeds them AI could earn trust in transactional work first How to fix keyboard connection issues on a remote desktop How to add and enroll devices to Microsoft Intune 11 DevSecOps best practices to prioritize in 2026 6 key components of a successful data strategy How to enable Copilot in Microsoft 365: A step-by-step guide What CIOs need to know about Meta's proposed CEO AI agent Top AI recruiting tools and software of 2026 How contact centers detect and prevent fraud 10 essential skills for modern contact center agents Beyond the chatbot: Engineering the agentic enterprise AI in business intelligence: How to manage it effectively Why legacy networks are a growing liability Failure is an option as an IT leadership tool How HR can create a successful change management strategy HR AI is becoming a change management story Digital transformation: Balancing speed and governance RSAC 2026 Conference: Key news and industry analysis | TechTarget 8 best practices for a bulletproof IAM strategy 5 customer journey phases businesses should understand 12 top HR software and tool options to consider in 2025 6 contact center trends shaping the future of customer service Contact center monitoring best practices for CX leaders Cloud vs. local backup: Which is right for your organization? 6 steps for when remote desktop credentials are not working How governance maturity affects M&A integration outcomes Inside the push to turn AI agents into suite functionality How should contact centers use AI today? Accenture global health lead on scaling AI in healthcare with governance and intent 10 best free DevOps certifications and training courses in 2026 What is compensation management? What CIOs must know about bossware strategy
Top identity and access management risks
Dave Shackleford · 2026-06-09 · via WhatIs

Identity is long past the days of logging into systems. Security teams must now manage SaaS apps, AI agents and machine-to-machine interactions across distributed environments.

Identity and access management has evolved from a supporting IT function into the foundation of enterprise security. In modern organizations, identity governs access not only for employees, but also for contractors, cloud workloads, SaaS platforms, APIs, automation pipelines and, increasingly, AI-driven systems and agents. It's common to hear identity described as the new perimeter.

Attackers no longer need to break in through traditional technical exploits if they can simply log in with stolen credentials, hijacked sessions, abused API tokens or compromised nonhuman identities (NHIs). At the same time, organizations struggle to manage sprawling SaaS ecosystems, cloud-native infrastructure, decentralized identity stores and autonomous AI systems.

All this means security teams face a mix of traditional IAM risks and newer identity challenges.

Overprivileged access remains one of the biggest risks

Users, administrators, service accounts and cloud roles often accumulate permissions over time that far exceed what they require. Organizations frequently grant broad access in the name of productivity; they rarely revisit or remove those privileges later.

In cloud environments, this problem is especially dangerous. A single overprivileged IAM role in AWS or Azure could provide access to sensitive data stores, administrative APIs, infrastructure provisioning or continuous delivery systems. Similarly, excessive permissions in SaaS platforms such as Microsoft 365, Salesforce, ServiceNow, GitHub or Slack can expose sensitive business data and operational workflows.

The risk is amplified because attackers increasingly target identities instead of infrastructure. Once an attacker compromises a privileged identity, they can often operate within the environment using legitimate APIs and trusted workflows, making detection significantly more difficult.

Organizations should prioritize least-privilege access, role reviews, entitlement governance and periodic access recertification processes. Modern IAM programs must extend these controls beyond traditional directory systems to include cloud-native and SaaS environments as well.

NHIs have become a major attack surface

A significant IAM development in recent years is the substantial rise in the number of NHIs. These include service accounts, API keys, OAuth tokens, cloud workload identities, containers, serverless functions, certificates, robotic process automation accounts and AI agents. In many organizations, NHIs dramatically outnumber human identities.

The challenge is that most IAM programs were originally designed around employees and contractors, not autonomous workloads operating continuously across cloud and SaaS environments. As a result, many NHIs are poorly governed, overprivileged, unmonitored or use long-lived credentials that are rarely rotated.

This creates significant risk. A compromised API token or cloud service role might provide direct access to production systems, sensitive data or deployment pipelines. Attackers increasingly target these identities because they often bypass traditional MFA and user-focused monitoring controls.

To secure NHIs, modern IAM programs should include:

  • Full inventory and ownership tracking of NHIs.
  • Automated credential rotation and short-lived tokens.
  • Workload identity federation where possible.
  • Least privilege access for service accounts and APIs.
  • Monitoring for anomalous workload identity behavior.
  • Separate governance models for human and machine identities.

NHI security is rapidly becoming one of the most important areas of IAM, particularly as organizations expand their use of cloud and AI services.

SaaS identity sprawl creates governance challenges

Most enterprises now operate hundreds or even thousands of SaaS applications. Many of these platforms maintain their own identity stores, roles, permissions and authentication methods.

Over time, organizations lose visibility into who has access to what, especially when individual business units adopt applications without centralized oversight.

This SaaS identity sprawl creates several risks:

  • Former employees retaining access to applications.
  • Excessive third-party OAuth integrations.
  • Shadow IT and unmanaged SaaS usage.
  • Weak MFA enforcement across platforms.
  • Inconsistent logging and monitoring.
  • Excessive administrative privileges in SaaS tools.

Attackers understand that SaaS applications often contain valuable business data, including intellectual property, financial information, customer records, collaboration data and source code. AI-powered attacks increasingly target SaaS platforms because identities and sessions are now easier to exploit at scale.

To address this, organizations should prioritize SaaS security posture management, centralized identity federation, conditional access enforcement, and continuous monitoring of SaaS privilege changes and OAuth grants.

AI-driven deepfakes and identity impersonation are rising threats

One of the newest IAM risks is the use of GenAI and deepfake technologies to impersonate employees, executives, help desk admins or business partners. With relatively little effort, attackers can generate convincing voice, video and text-based impersonations to:

  • Trick the help desk into resetting a password for a privileged employee or executive account.
  • Illegitimately request MFA resets by impersonating employees who claim to have lost or replaced devices.
  • Impersonate executives in urgent financial, legal or operational communications.
  • Bypass voice-authentication systems used in banking, customer service or internal verification workflows.
  • Conduct business email compromise campaigns using synthetic voice or video to reinforce legitimacy.
  • Infiltrate vendor-payment workflows involving fraudulent invoice approvals or wire-transfer requests.

Deepfake-enabled social engineering and phishing are particularly dangerous because it targets the human trust layer of IAM processes rather than technical systems. Organizations that rely heavily on voice recognition or weak verification procedures could find these attacks increasingly difficult to detect.

Security teams should revisit all high-risk identity recovery and reset workflows. Stronger identity proofing, phishing-resistant MFA, callback verification procedures, privileged-access approvals and risk-based authentication controls are becoming essential.

The help desk itself is increasingly becoming a security-sensitive function and should be treated as part of the organization's identity attack surface.

Identity-centric attacks provide efficient entry points

Identity-based attacks remain one of the most common initial access vectors for breaches. Stolen credentials, session hijacking, token theft, MFA bypassing and compromised federated identities continue to drive major incidents across industries.

Attackers prefer these methods because they are efficient and often bypass traditional perimeter defenses. In cloud environments especially, valid credentials could provide direct access to sensitive resources without requiring malware or exploit chains.

This trend reinforces the need for phishing-resistant MFA, conditional access policies, continuous session validation, identity threat detection and response, device trust validation, impossible travel and anomalous behavior monitoring, and session-token protection.

Modern IAM increasingly requires continuous evaluation of identity risk throughout a session, not just at login, in line with zero-trust practices.

Weak identity governance still causes major problems

Despite advances in IAM technology, organizations still struggle with governance fundamentals, such as orphaned accounts, delayed deprovisioning, role explosion, excessive administrative access, inconsistent approval workflows and lack of ownership for identities and entitlements.

These issues become even more difficult in hybrid environments, where identities span on-premises systems, cloud infrastructure, SaaS platforms, contractors and machine identities. AI and automation can improve governance processes, but they increase complexity if organizations deploy them without strong oversight. Autonomous systems and AI agents might request or inherit permissions dynamically, creating new governance challenges around delegation, accountability and auditability.

CISOs and their organizations should focus on building identity governance programs that emphasize more progressive controls, such as just-in-time privileged access, continuous access reviews and automated deprovisioning. Even with these controls, many modern IAM programs will fail without strong lifecycle management and policies, enterprise-wide identity ownership and accountability, and a commitment to risk-based entitlement governance across all platforms and systems.

While least privilege, strong authentication, lifecycle management, governance and monitoring still matter, those fundamentals are not enough. IAM programs must evolve from static authentication systems into continuous trust and verification platforms. Organizations that continue to treat IAM as a directory management problem will struggle to keep pace with modern threats.

Dave Shackleford is founder and principal consultant at Voodoo Security, as well as a SANS analyst, instructor and course author, and GIAC technical director.

Next Steps

Best practices for a bulletproof IAM strategy

Key identity and access management benefits

IAM compliance: Know the system controls at your disposal

How to build an effective IAM architecture

Dig Deeper on Identity and access management