Cloud Vulnerabilities: 115+ Found in Assets
- Identity-based threats represent a serious and frequently exploited vulnerability in cloud environments.
- these threats frequently target non-human identities (NHIs), including API keys, access tokens, service accounts, cloud functions, and machine identities.
- One expert noted the exponential growth of NHIs, stating that they outnumber human users by a factor of 50.
Identity-Based Threats Pose Cloud Security Risks
Updated June 10,2025
Identity-based threats represent a serious and frequently exploited vulnerability in cloud environments. according to a recent report, this attack vector ranks as the second most common initial access point, yet it frequently enough proves to be the most vulnerable.
these threats frequently target non-human identities (NHIs), including API keys, access tokens, service accounts, cloud functions, and machine identities. The proliferation of NHIs considerably expands the attack surface.
One expert noted the exponential growth of NHIs, stating that they outnumber human users by a factor of 50. Leaving these identities unsecured can rapidly escalate cloud risks, particularly when NHIs are granted excessive privileges.
Data indicates that a significant percentage of organizations using AWS operate service accounts with access to multiple accounts. Furthermore, a portion of these accounts possess excessive roles across numerous instances. Many of these roles remain unused after their creation, and a large percentage of IAM certificates remain inactive for extended periods, creating potential vulnerabilities in cloud security.
What’s next
organizations must prioritize securing non-human identities and regularly review and revoke unnecessary permissions to mitigate cloud security risks.
