
OWASP NHI5:2025 - Overprivileged NHI In-Depth Analysis and Management
Why service accounts and API keys end up with more privilege than they need, and how A2A and MCP raise the stakes.

Learn from experts, understand everything you need to know about compliance, and find answers to your pressing security questions.
We use cookies to measure traffic and ad performance. Declining costs you nothing: the site keeps working, and all that stays is your language and this answer. Everything we load is listed in the cookie policy

Why service accounts and API keys end up with more privilege than they need, and how A2A and MCP raise the stakes.


Lifecycle management and scheduled rotation leave a window open. What continuous detection covers inside it.


Research puts NHIs at roughly 46 per person, and 45 times the human count in DevOps. What weak authentication costs at that scale.


Where credentials leak in modern CI/CD pipelines, what to scan at each stage (pre-commit, build, deploy), and how to integrate secret detection without slowing delivery.


Model Context Protocol (MCP) and Agent-to-Agent (A2A) communication are redrawing the NHI security boundary. What changes when AI agents become first-class identities in your infrastructure.


Moving secret detection left without slowing delivery. What it costs to catch a key before the commit versus after the deploy.


Credentials ride into S3 buckets alongside backups and config files. How they get there, and why they surface late.


Breach costs keep climbing. Which part of that number secret detection actually reduces.


Human and machine accounts are issued, owned and revoked differently. Where a single process for both leaves gaps.


A GitHub Action used by more than 23,000 repositories was altered and its version tags retagged, leaking CI/CD secrets into build logs. The incident read as an NHI failure.


Secrets enter a codebase through a short list of familiar routes. What to check on each one.


Service accounts and tokens that outlive their purpose are the easiest targets in the estate. What OWASP NHI1:2025 says about offboarding.

Short monthly brief from the Cremit research team.