惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
V
Visual Studio Blog
T
Tor Project blog
量子位
Jina AI
Jina AI
Hugging Face - Blog
Hugging Face - Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
有赞技术团队
有赞技术团队
博客园 - 司徒正美
博客园_首页
罗磊的独立博客
美团技术团队
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
C
Check Point Blog
博客园 - 聂微东
爱范儿
爱范儿
Schneier on Security
Schneier on Security
T
Threat Research - Cisco Blogs
T
Tailwind CSS Blog
L
LINUX DO - 热门话题
大猫的无限游戏
大猫的无限游戏
V
Vulnerabilities – Threatpost
C
Cisco Blogs
GbyAI
GbyAI
Spread Privacy
Spread Privacy
博客园 - 叶小钗
博客园 - 【当耐特】
T
Tenable Blog
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
J
Java Code Geeks
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
宝玉的分享
宝玉的分享
Microsoft Azure Blog
Microsoft Azure Blog
Simon Willison's Weblog
Simon Willison's Weblog
N
Netflix TechBlog - Medium
T
The Exploit Database - CXSecurity.com
腾讯CDC
C
CERT Recently Published Vulnerability Notes
P
Proofpoint News Feed
阮一峰的网络日志
阮一峰的网络日志
Scott Helme
Scott Helme
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Martin Fowler
Martin Fowler

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber Microsoft patched an ‘agent-only’ role that was not AI is reshaping DevSecOps to bring security closer to the code The 'manager of agents': How AI evolves the SOC analyst role 4 Wege aus der Security-Akronymhölle Autonome KI-Agenten: Strategien für die neue Bedrohungslage New US House privacy bills raise hard questions about enterprise data collection Scattered Spider co-conspirator pleads guilty Security-KPIs und -KRIs: So messen Sie Cybersicherheit Bitwarden CLI password manager trojanized in supply chain attack 3 practical ways AI threat detection improves enterprise cyber resilience The curious case of Sean Plankey’s derailed CISA nomination Google gets agent-ready for the Mythos age Google drafts AI agents secure systems against AI hackers CNAPP – ein Kaufratgeber Riddled with flaws, serial-to-Ethernet converters endanger critical infrastructure NFC tap-to-pay gets tapped by hackers Anthropic bets on EPSS for the coming bug surge SBOM erklärt: Was ist eine Software Bill of Materials? Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered Prompt injection turned Google’s Antigravity file search into RCE Why identity is the driving force behind digital transformation Top techniques attackers use to infiltrate your systems today The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops Attackers abuse Microsoft Teams to impersonate the IT helpdesk in a new enterprise intrusion playbook CISOs reshape their roles as business risk strategists Copilot & Agentforce offen für Prompt-Injection-Tricks Claude Mythos – ist der Hype gerechtfertigt? Für Cyberattacken gewappnet – Krisenkommunikation nach Plan Critical sandbox bypass fixed in popular Thymeleaf Java template engine White House moves to give federal agencies access to Anthropic’s Claude Mythos Another Microsoft Defender privilege escalation bug emerges days after patch Palo Alto’s Helmut Reisinger sees a cyber sea change ahead as AI advances Positiv denken für Sicherheitsentscheider: 6 Mindsets, die Sie sofort ablegen sollten NIST cuts down CVE analysis amid vulnerability overload Was bei der Cloud-Konfiguration schiefläuft – und wie es besser geht The endless CISO reporting line debate — and what it says about cybersecurity leadership Behind the Mythos hype, Glasswing has just one confirmed CVE Insurance carriers quietly back away from covering AI outputs RCE by design: MCP architectural choice haunts AI agent ecosystem Critical nginx UI tool vulnerability opens web servers to full compromise Copilot and Agentforce fall to form-based prompt injection tricks The deepfake dilemma: From financial fraud to reputational crisis 7 biggest healthcare security threats The need for a board-level definition of cyber resilience Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action 13 Fragen gegen Drittanbieterrisiken April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs 4 questions to ask before outsourcing MDR 5 trends defining the future of AI-powered cybersecurity EU regulators largely denied access to Anthropic Mythos China-linked cloud credential heist runs on typos and SMTP How AI is transforming threat detection The AI inflection point: What security leaders must do now Cyber-Inspekteur: Hybride Attacken nehmen weiter zu Anthropic’s Mythos signals a structural cybersecurity shift Seven IBM WebSphere Liberty flaws can be chained into full takeover Old Docker authorization bypass pops up despite previous patch Hacker Unknown now known, named on Europol’s most-wanted list The cyber winners and losers in Trump’s 2027 budget CMMC compliance in the age of AI Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes Was CISOs von Moschusochsen lernen können Hackers have been exploiting an unpatched Adobe Reader vulnerability for months New ClickFix variant bypasses Apple safeguards with one‑click script execution Cloudflare ‘actively adjusting’ quantum priorities in wake of Google warning Patch windows collapse as time-to-exploit accelerates So geht Post-Incident Review
Governing the ghost workforce
Ashish Mishra · 2026-06-15 · via CSO Online

Why non-human identities are your biggest business continuity risk in 2026.

Every enterprise security team is fighting a workforce problem they cannot see on any org chart.

Bots, service accounts, API keys, OAuth tokens, machine certificates — non-human identities now outnumber human ones in most large organisations, often by a factor of ten to one. They authenticate constantly, operate across every environment, and when forgotten, they do not retire gracefully. They linger, accumulate privilege, and wait. Security practitioners have taken to calling them ghost identities — and the name fits.

The security industry has had plenty of warnings. It just has not acted on it.

Cast your mind back to SolarWinds story. The attackers did not smash through anything. They slipped in, found machine identities with significant access, and used them the way they were designed to be used — quietly, legitimately, invisibly. Eighteen thousand organisations. Months undetected. The credentials were not stolen in the traditional sense. They were just there, unmonitored, doing what attackers needed them to do.

Uber, 2022. Simpler anatomy. A service account nobody owned. Credentials that had not been rotated in who knows how long. Found in a network share by an attacker who was already looking. That one ghost identity opened a direct path to the PAM system — and from there, everything else followed. Cloud environments. Source code. Internal tools. One forgotten credential. That was the price of admission.

Okta, 2023. Different problem, harder to solve. The credentials that mattered were not even on Okta’s own infrastructure. They lived with a third-party support vendor. Technically, someone else’s environment. But they carried access rights into Okta’s systems, and when that vendor was compromised, the pathway was compromised too.

Three incidents. Three different entry points. One thing in common — an identity that nobody was watching, carrying access nobody had recently justified, sitting exactly where an attacker needed it to be.

Calling this a security problem is not wrong. It just does not cover what is coming next.

The scheduled crisis

In 2026, the consequences of unmanaged non-human identities take a new form. Not a breach. A calendar event.

Machine identity certificates have finite lifespans. For much of the past decade, organisations issued them with validity windows of three to five years. Between 2020 and 2022, enterprises expanded their digital infrastructure at extraordinary speed — cloud migrations compressed into months, automation pipelines stood up under pressure, and new services connecting to other services with governance as an afterthought.

Those certificates are expiring now. Not in ones and twos. In volume.

The cascading failure scenario is not complicated. A certificate expires unnoticed. The service it supports drops. Dependent applications that are authenticated through that service start failing. Monitoring tools running on the same infrastructure miss the alert. The incident response team works on the problem without a complete picture of what connects to what. Hours pass. Sometimes a full day. What started as an overlooked credential with an expiry date becomes an outage with a revenue figure attached and a regulator taking notes.

This has happened before on a smaller scale — a single expired certificate took Microsoft Teams offline for millions of users in 2020. What 2026 presents is the same failure mode, replicated across organisations that grew fast and governed poorly, hitting simultaneously.

Certificate expiration is habitually treated as an IT operations issue. That framing does not survive contact with an outage that takes customer-facing services down for eighteen hours.

Figure: The cascading failure chain.
Figure 1: The cascading failure chain.

Ashish Mishra

The structural gap

The root cause is not negligence. It is architecture.

The tools organisations rely on to manage identity — role-based access controls, privileged access management platforms, access certification campaigns — were built for people. They assume an identity has an owner, a manager, and a review cycle. Non-human identities do not fit that model. They get created to solve an immediate problem, granted broad access to make the thing work, and left running long after the project moves on.

Over-provisioning compounds the risk. Every unreviewed service account is a potential pivot point. Every dormant API key with write access is an open door. For ghost identities carrying legacy admin rights — and there are more of them than most organisations want to admit — the blast radius of a compromise is often organisation-wide.

What good looks like

The answer is not a tool. Every vendor in this space will tell you otherwise. They are wrong about the order of operations.

Governance comes first. Tooling supports it. And governance starts with a question most organisations cannot currently answer: what non-human identities are we running?

That question sounds simple. It is not. NHIs do not get created centrally. They get created by developers solving problems, by platform teams standing up services, by vendors connecting their products to yours. Each decision made sense at the time. None of them got logged somewhere useful. The result, in most large enterprises, is an estate that nobody has a complete map of — and that no tool can govern until someone builds one.

So, start there. Not with a platform evaluation. Not with a policy document. With a discovery sprint. Four to six weeks, focused on your highest-risk environments. Cloud first. CI/CD pipelines. Third-party integrations. An imperfect inventory is still infinitely more useful than operating blind.

While that work is running, pull your certificate expiration data. Today, not next quarter. Sort by expiry date. Filter for anything lapsing in the next eighteen months. Put a named owner against every entry — and where no owner can be identified, treat the certificate as a ghost identity. Escalate it accordingly. This one action directly addresses the 2026 expiration risk before it becomes an outage.

Last, run a privilege audit on your highest-sensitivity service accounts. Any NHI with admin rights that has not been reviewed in the past twelve months should be treated as over-privileged until the evidence says otherwise. Assume excess. Prove necessity.

None of this needs a new budget line. It needs someone to decide it is worth doing before the alternative decides for them.

The broader problem

One organisation fixing its NHI estate does not fix the problem. It just means one organisation is less exposed than the rest.

The market around machine identity is still finding its feet. Ask three vendors to define the scope of NHI governance, and you will get three different answers. Lifecycle standards that should exist do not. The frameworks security teams rely on — NIST, ISO 27001 — address least privilege as a concept but stop well short of telling anyone what to do with fifty thousand unmanaged service accounts spread across a hybrid cloud environment.

What is missing is not ambition. It is specificity. Agreed taxonomy. Shared lifecycle standards. Regulatory guidance that puts NHI governance on the same level as every other identity obligation — not buried in a footnote, not implied by a principle, but stated plainly and enforced accordingly.

That conversation is happening. Standards bodies are moving. Regulators are paying closer attention. But the pace is measured in years, and the certificate expiration wave is measured in months.

The expiry dates do not wait for the industry to catch up.

The deadline is built in

The ghost workforce does not announce itself. It does not resign or ask for a performance review. It runs until something stops it — a breach, an expiration, or a security team that finally decided to take inventory.

In 2026, for organisations that have not mapped and governed their NHI estate, something is going to stop it. The only variable is whether that something is a deliberate programme or an unplanned outage.

The runway is very thin.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

Ashish Mishra

Ashish Mishra is a seasoned IT professional and author with over 20 years of experience in the industry. He holds a strong grip and command of IT, information security and cybersecurity domains. Ashish is also experienced in managing large IT and IS operations, strategy building, transformation journeys, project and program management, and service delivery. His technical areas of expertise include, but are not limited to, public cloud, private cloud, cloud security, network security, SASE and zero trust.

Adhering to the principle of "continuous learning is the key to success," Ashish has obtained more than 125 professional certifications across various technologies and platforms related to public and private cloud, cloud security, information security, cybersecurity, compliance, artificial intelligence, infrastructure management, leadership, project management and others.

More from this author

Show me more