A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API … More →
The post Non-human identities are 91% of everything active in production appeared first on Help Net Security.
http://news.poseidon-us.com/TTtMC7





