Skip to main content
NEW: RSAC 2026 NHI Field Report. How Non-Human Identity became cybersecurity's central axis
Back to Blog
Tag

NHI Security

39 posts
Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.
Aug 5, 2026

Your Dashboard Says 14,000 Secrets. The Number That Matters Is 525.

Every secret scanner hands you a big number, and almost nobody can act on it. When we verified each finding against the service that issued it, a five-figure detection count became a three-figure inventory of credentials that actually work. This is what that collapse means for how you prioritize, what you suppress, and what you tell your board.

Ben Kim
Ben Kim
Founder & CEO
From Research to Product: How Cremit Built Argus to Solve the NHI Security Gap
Jul 28, 2026

From Research to Product: How Cremit Built Argus to Solve the NHI Security Gap

We spent six months documenting why non-human identity (NHI) security fails in real organizations, from bug bounties that call leaked keys "out of scope" to the nine-part NHI Kill Chain. Argus is the product we built from what that research proved.

Ben Kim
Ben Kim
Founder & CEO
AI Agents Rerun the Service-Account Mistake: The Governance Gap Nobody Sized
Jul 19, 2026

AI Agents Rerun the Service-Account Mistake: The Governance Gap Nobody Sized

Every agent action is a credential action, and the industry is treating a governance shift as a provisioning task, exactly the way it did with service accounts.

Ben Kim
Ben Kim
Founder & CEO
The Identity You Can't See Is the One That Breaks You
Jul 15, 2026

The Identity You Can't See Is the One That Breaks You

The Korean GitHub token leaks and CISA's public-repo exposure were both filed as secrets leaks. What got out was not a file but a live identity. This piece argues that security leaders should treat API keys as identities and shift the defense from prevention rate to how fast you detect what has already leaked.

Ben Kim
Ben Kim
Founder & CEO
Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel
Jun 13, 2026

Your Slack Webhook Is Write-Only, Until an AI Agent Reads the Channel

A leaked Slack incoming webhook is usually triaged as low severity: write-only, one channel, no data access. The moment an AI agent reads that channel and can act with tools, that write-only primitive becomes an indirect prompt injection path into the agent's privileges. Here is the full kill chain, the exact preconditions, and how to defend it.

Ben Kim
Ben Kim
Founder & CEO
AntV npm Compromise: How Cremit's Argus Pipeline Surfaced 324 Mini Shai-Hulud Catches Within 30 Minutes
May 19, 2026

AntV npm Compromise: How Cremit's Argus Pipeline Surfaced 324 Mini Shai-Hulud Catches Within 30 Minutes

Between 01:39 and 02:56 UTC on May 19, 2026, two tight publish bursts placed 639 malicious versions across 323 packages on npm. The single stolen `atool` session was only the entry point. The payload's worm logic harvested every additional maintainer npm token on the infected host and republished under those identities, which is why the wave spans 30 publisher handles. Cremit Argus surfaced 324 catches within thirty minutes via an OSV-MAL override path that intentionally bypasses LLM agreement for OSSF-flagged events. This article documents the attack structure, the detection methodology, and the false-positive trap that nearly slipped past during initial analysis.

Ben Kim
Ben Kim
Founder & CEO
NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)
Apr 30, 2026

NHI Kill Chain: 8 Ways Your Credentials Are Already Compromised (And the One Fix That Addresses All of Them)

Eight types of dangerous NHI credentials. One framework to find, classify, and eliminate them all. The complete NHI Kill Chain series summary with Cyber Kill Chain and MITRE ATT&CK mapping.

Ben Kim
Ben Kim
Founder & CEO
Bitwarden CLI Hack (April 2026): How a 90-Minute npm Window Stole AWS, GCP, GitHub Tokens
Apr 25, 2026

Bitwarden CLI Hack (April 2026): How a 90-Minute npm Window Stole AWS, GCP, GitHub Tokens

On April 22, 2026, the official @bitwarden/cli@2026.4.0 npm package was malicious for ~90 minutes. A self-propagating worm exfiltrated AWS, Azure, GCP, GitHub, npm, SSH, and AI tooling credentials from CI runners. Vaults stayed safe. CI tokens did not. Timeline, NHI kill-chain mapping, and a 10-minute checklist to know whether you were affected.

Ben Kim
Ben Kim
Founder & CEO
Vercel's April 2026 Incident Is a Textbook NHI Problem: What to Rotate and Why
Apr 20, 2026

Vercel's April 2026 Incident Is a Textbook NHI Problem: What to Rotate and Why

Vercel confirmed an unauthorized-access incident on April 19, 2026 that started in a third-party AI tool, pivoted through Google Workspace, and reached environment variables in a subset of customer projects. The exposure surface is every env var that was not marked sensitive. Here is what is confirmed, what is noise, and what to rotate first.

Ben Kim
Ben Kim
Founder & CEO
Ownerless API Keys: When 60% of Your Credentials Have No Identifiable Owner (NHI Kill Chain #8)
Apr 20, 2026

Ownerless API Keys: When 60% of Your Credentials Have No Identifiable Owner (NHI Kill Chain #8)

A new CISO ordered a full NHI audit. The result: 3,400 active credentials, 60% with no identifiable owner. Can't revoke them, can't rotate them, can't assign responsibility.

Ben Kim
Ben Kim
Founder & CEO
Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)
Apr 17, 2026

Credential Sprawl: How One Database Password Spread to 7 Platforms (NHI Kill Chain #6)

A PostgreSQL master password drifted across seven platform types, from Secrets Manager to GitHub, Jenkins, Docker Hub, Jira, Confluence and Slack. Each security tool saw its own silo. None saw the full picture.

Ben Kim
Ben Kim
Founder & CEO
The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure
Apr 15, 2026

The "Out of Scope" Loophole: Why Bug Bounties Look Away From Credential Exposure

An organization's core credentials sat in public repositories for years. The security industry's answer: "Out of scope."

Ben Kim
Ben Kim
Founder & CEO
Expired Credentials That Still Work: The Zombie Key Problem (NHI Kill Chain #5)
Apr 14, 2026

Expired Credentials That Still Work: The Zombie Key Problem (NHI Kill Chain #5)

Secret scanning alert: Resolved. Credential status: Active. Deleting a secret from code is not the same as revoking it. Inside the Zombie Key kill chain.

Ben Kim
Ben Kim
Founder & CEO
Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)
Apr 11, 2026

Over-privileged API Keys: When One Credential Unlocks Too Much (NHI Kill Chain #4)

A single Stripe API key was copied to 14 locations over three years. When a QA repo went public, the key was exposed, and revoking it meant breaking 14 services at once.

Ben Kim
Ben Kim
Founder & CEO
Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)
Apr 10, 2026

Unrotated API Keys: Why Years-Old Credentials Still Run Production (NHI Kill Chain #3)

A single AWS key, never rotated for 3 years, spread across 7 systems. When a supply chain attack hit a Terraform CI plugin, the key gave attackers full infrastructure access. Inside the Aged Key kill chain and how to defend against long-lived credentials.

Ben Kim
Ben Kim
Founder & CEO
Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)
Apr 5, 2026

Shadow Service Accounts: Detecting Undocumented Machine Identities (NHI Kill Chain #2)

A single production outage left credentials in six non-code platforms: Slack, Jira, Confluence, Sentry, Datadog and PagerDuty. Your secret scanner found none of them. Inside the Shadow Key kill chain.

Ben Kim
Ben Kim
Founder & CEO
Orphaned API Keys: The Security Risk of Credentials With No Owner (NHI Kill Chain #1)
Apr 2, 2026

Orphaned API Keys: The Security Risk of Credentials With No Owner (NHI Kill Chain #1)

A departed developer's AWS key stayed active for 92 days. When an infostealer hit their personal laptop, the key was sold on the dark web. Inside the Ghost Key kill chain and how to defend against orphaned credentials.

Ben Kim
Ben Kim
Founder & CEO
When the Security Scanner Became the Weapon: A Cyber Kill Chain Analysis of the Trivy Supply Chain Attack
Mar 25, 2026

When the Security Scanner Became the Weapon: A Cyber Kill Chain Analysis of the Trivy Supply Chain Attack

Aqua Security's Trivy was compromised by TeamPCP, cascading into LiteLLM. A 7-phase Cyber Kill Chain and MITRE ATT&CK analysis of how incomplete credential rotation turned a single breach into a five-ecosystem catastrophe.

Ben Kim
Ben Kim
Founder & CEO
Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)
Mar 17, 2026

Publicly Exposed API Keys: What Happens When Credentials Reach Open Repos (NHI Kill Chain #7)

A .env file pushed to a public GitHub repo is found by attacker bots in 4 minutes. We map the full kill chain, from credential exposure to infrastructure compromise, and show how to detect and respond before the damage is done.

Ben Kim
Ben Kim
Founder & CEO
How a Single GitHub Issue Title Compromised 4,000 Developer Machines
Mar 7, 2026

How a Single GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection in a GitHub Issue title hijacked Cline's AI triage bot, stole npm tokens, and silently installed a rogue AI agent on 4,000 developer machines. The era of AI-installing-AI supply chain attacks has arrived.

Ben Kim
Ben Kim
Founder & CEO
The 2025 Cybersecurity Landscape: Download the Full Report
May 29, 2025

The 2025 Cybersecurity Landscape: Download the Full Report

The Cremit team's report on identity and detection trends for 2025, available to download in full.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI5:2025 - Overprivileged NHI In-Depth Analysis and Management
Apr 25, 2025

OWASP NHI5:2025 - Overprivileged NHI In-Depth Analysis and Management

Why service accounts and API keys end up with more privilege than they need, and how A2A and MCP raise the stakes.

Ben Kim
Ben Kim
Founder & CEO
Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security
Apr 23, 2025

Beyond Lifecycle Management: Why Continuous Secret Detection is Non-Negotiable for NHI Security

Lifecycle management and scheduled rotation leave a window open. What continuous detection covers inside it.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI4:2025 Insecure Authentication Deep Dive Introduction: The Era of Non-Human Identities Beyond Humans
Apr 22, 2025

OWASP NHI4:2025 Insecure Authentication Deep Dive Introduction: The Era of Non-Human Identities Beyond Humans

Research puts NHIs at roughly 46 per person, and 45 times the human count in DevOps. What weak authentication costs at that scale.

Ben Kim
Ben Kim
Founder & CEO
MCP and A2A: Why Non-Human Identity Security Matters in the AI Era
Apr 16, 2025

MCP and A2A: Why Non-Human Identity Security Matters in the AI Era

Model Context Protocol (MCP) and Agent-to-Agent (A2A) communication are redrawing the NHI security boundary. What changes when AI agents become first-class identities in your infrastructure.

Ben Kim
Ben Kim
Founder & CEO
Human vs. Non-Human Identity: The Key Differentiators
Apr 1, 2025

Human vs. Non-Human Identity: The Key Differentiators

Human and machine accounts are issued, owned and revoked differently. Where a single process for both leaves gaps.

Ben Kim
Ben Kim
Founder & CEO
Wake-Up Call: tj-actions/changed-files Compromised NHIs
Mar 25, 2025

Wake-Up Call: tj-actions/changed-files Compromised NHIs

A GitHub Action used by more than 23,000 repositories was altered and its version tags retagged, leaking CI/CD secrets into build logs. The incident read as an NHI failure.

Ben Kim
Ben Kim
Founder & CEO
Behind the Code: Best Practices for Identifying Hidden Secrets
Mar 18, 2025

Behind the Code: Best Practices for Identifying Hidden Secrets

Secrets enter a codebase through a short list of familiar routes. What to check on each one.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI1:2025 Improper Offboarding- A Comprehensive Overview
Mar 3, 2025

OWASP NHI1:2025 Improper Offboarding- A Comprehensive Overview

Service accounts and tokens that outlive their purpose are the easiest targets in the estate. What OWASP NHI1:2025 says about offboarding.

Ben Kim
Ben Kim
Founder & CEO
Stop the Sprawl: Introducing Cremit’s AWS S3 Non-Human Identity Detection
Feb 25, 2025

Stop the Sprawl: Introducing Cremit’s AWS S3 Non-Human Identity Detection

S3 buckets accumulate the machine roles, automated services and API keys that read and write to them. Cremit now scans those buckets continuously with read-only access and returns the inventory.

Ben Kim
Ben Kim
Founder & CEO
Build vs. Buy: Making the Right Choice for Secrets Detection
Feb 25, 2025

Build vs. Buy: Making the Right Choice for Secrets Detection

Building secret detection or buying it. The factors that actually decide it, one at a time.

Ben Kim
Ben Kim
Founder & CEO
Bybit Hack Analysis: Strengthening Crypto Exchange Security
Feb 18, 2025

Bybit Hack Analysis: Strengthening Crypto Exchange Security

Bybit lost 401,347 ETH, about $1.4 billion, on February 21. How the attack worked, and what it changes for exchange security.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI2:2025 Secret Leakage – Understanding and Mitigating the Risks
Feb 18, 2025

OWASP NHI2:2025 Secret Leakage – Understanding and Mitigating the Risks

OWASP NHI2:2025 covers API keys and tokens ending up in stores that were never meant to hold them. Where they leak, and how to stop it.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI3:2025 - Vulnerable Third-Party NHI
Feb 4, 2025

OWASP NHI3:2025 - Vulnerable Third-Party NHI

Third-party integrations reach into your resources with credentials you never issued. What OWASP NHI3:2025 covers, and where the exposure sits.

Ben Kim
Ben Kim
Founder & CEO
6 Essential Practices for Protecting Non-Human Identities
Dec 5, 2024

6 Essential Practices for Protecting Non-Human Identities

Six practices for keeping credentials out of reach: vaulting, least privilege, rotation and the rest.

Ben Kim
Ben Kim
Founder & CEO
Introducing Probe! Cremit's New Detection Engine
Aug 3, 2024

Introducing Probe! Cremit's New Detection Engine

Regex-based scanners miss credential formats nobody told them about. What Probe, Cremit’s detection engine, does differently.

Ben Kim
Ben Kim
Founder & CEO
OWASP NHI Top 10 Explained: 10 Machine-Credential Risks Mapped
Apr 9, 2024

OWASP NHI Top 10 Explained: 10 Machine-Credential Risks Mapped

OWASP NHI Top 10 names the machine-credential risks most teams still do not track. Here is what each threat means, and how each maps to real controls you can deploy.

Ben Kim
Ben Kim
Founder & CEO
Customer Interview: Insights from ENlighten
Mar 4, 2024

Customer Interview: Insights from ENlighten

A conversation with the team at ENlighten, a Korean energy IT platform, about how they manage credentials and secrets and what led them to Cremit.

Ben Kim
Ben Kim
Founder & CEO
Secret Sprawl and Non-Human Identities: The Growing Security Challenge
Oct 22, 2023

Secret Sprawl and Non-Human Identities: The Growing Security Challenge

Secret sprawl stopped being a password problem and became an identity one. Where credentials accumulate, and what detection actually reduces.

Ben Kim
Ben Kim
Founder & CEO
NHI Security | Cremit Blog | Cremit