
AI Agents Rerun the Service-Account Mistake: The Governance Gap Nobody Sized
Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.


Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.


Eight types of dangerous NHI credentials. One framework to find, classify, and eliminate them all. The complete NHI Kill Chain series summary with Cyber Kill Chain and MITRE ATT&CK mapping.


A new CISO ordered a full NHI audit. The result: 3,400 active credentials, 60% with no identifiable owner. Can't revoke them, can't rotate them, can't assign responsibility.


A PostgreSQL master password drifted across seven platform types, from Secrets Manager to GitHub, Jenkins, Docker Hub, Jira, Confluence and Slack. Each security tool saw its own silo. None saw the full picture.


A single Stripe API key was copied to 14 locations over three years. When a QA repo went public, the key was exposed, and revoking it meant breaking 14 services at once.


A single AWS key, never rotated for 3 years, spread across 7 systems. When a supply chain attack hit a Terraform CI plugin, the key gave attackers full infrastructure access. Inside the Aged Key kill chain and how to defend against long-lived credentials.


A single production outage left credentials in six non-code platforms: Slack, Jira, Confluence, Sentry, Datadog and PagerDuty. Your secret scanner found none of them. Inside the Shadow Key kill chain.


A departed developer's AWS key stayed active for 92 days. When an infostealer hit their personal laptop, the key was sold on the dark web. Inside the Ghost Key kill chain and how to defend against orphaned credentials.


Aqua Security's Trivy was compromised by TeamPCP, cascading into LiteLLM. A 7-phase Cyber Kill Chain and MITRE ATT&CK analysis of how incomplete credential rotation turned a single breach into a five-ecosystem catastrophe.


A prompt injection in a GitHub Issue title hijacked Cline's AI triage bot, stole npm tokens, and silently installed a rogue AI agent on 4,000 developer machines. The era of AI-installing-AI supply chain attacks has arrived.


We found live API keys in 0.45% of public Vercel deployments. AWS credentials, Stripe secrets, GitHub tokens. Here is what exposes them (NEXT_PUBLIC_ misuse is only one), how attackers chain a single key into full cloud compromise, and what to change in your setup this week.


Credentials ride into S3 buckets alongside backups and config files. How they get there, and why they surface late.


S3 buckets accumulate the machine roles, automated services and API keys that read and write to them. Cremit now scans those buckets continuously with read-only access and returns the inventory.


Cremit has joined the AWS SaaS Spotlight program for early-stage SaaS startups in Asia Pacific.

We use cookies to measure traffic and ad performance. Declining costs you nothing: the site keeps working, and all that stays is your language and this answer. Everything we load is listed in the cookie policy