Non-human identities are 91% of everything active in production
Overview
A recent report reveals that non-human identities, such as automated processes and machines, account for 91% of all activity in production environments. This includes tasks like backup jobs, scanning, and logging, often occurring outside of standard business hours. The research indicates that only 20% of this non-human activity takes place during regular office hours, which raises concerns about security. If attackers gain access to credentials associated with these machine identities, they can operate undetected, posing significant risks to organizations. This situation emphasizes the need for improved credential management and monitoring to prevent unauthorized access and potential breaches.
Key Takeaways
- Affected Systems: AWS accounts, automated processes, machine identities
- Action Required: Implement stronger credential management practices, enhance monitoring of non-human activity, and establish stricter access controls for machine identities.
- Timeline: Newly disclosed
Original Article Summary
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API … More → The post Non-human identities are 91% of everything active in production appeared first on Help Net Security.
Impact
AWS accounts, automated processes, machine identities
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Implement stronger credential management practices, enhance monitoring of non-human activity, and establish stricter access controls for machine identities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Amazon.