bleeping-computer · Crawled Jul 10, 2026
The Replicant in Your Directory: AI Agents and the Identity Security Gap
1 Actors
Read original article ↗
AI Summary
The article discusses how AI agents and machine identities are outpacing traditional identity governance, creating a growing security gap. These non-human identities, such as service accounts and OAuth applications, often inherit excessive permissions and persist long after their original purpose, increasing the attack surface. A notable incident involved threat actor UNC6395 exploiting a trusted OAuth token from Salesloft's Drift integration to pivot across Salesforce, AWS, and Snowflake environments. The core issue is not new vulnerabilities, but the lack of ownership, visibility, and lifecycle management for machine identities.
AI-extracted · verify before operational use
Extracted Entities 1 found
MITRE ATT&CK TTPs 10 techniques
T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195.002 Compromise Software Supply Chain · Initial Access T1212 Exploitation for Credential Access · Credential Access T1213 Data from Information Repositories · Collection T1499 Endpoint Denial of Service · Impact T1558 Steal or Forge Kerberos Tickets · Credential Access T1566.002 Spearphishing Link · Initial Access