Report: "Automated identities"... a hidden cyber threat grows as the use of artificial intelligence expands
Cybersecurity experts warned of the growing risks associated with what are known as "automated identities", which are the accounts and credentials used by systems, software and devices to communicate with each other, stressing that this type of identities has become one of the biggest security challenges facing organizations in light of the rapid expansion in the use of artificial intelligence and digital services.
And according to a recent report, the number of automatic identities within institutions exceeds the number of human users by more than a hundred times, while this number continues to rise annually, at a time when most security measures focus on confronting human attackers, while automatic identities receive less attention despite having broad powers and ability to work permanently.
And the report pointed out that the credentials of systems, such as access codes and service accounts, often remain effective for long periods or do not expire, making their breach a great risk, as attackers can exploit them to access systems and steal data without raising suspicions.
The report cited several high-profile incidents, including a breach in 2020 of British Airways using unupdated credentials, as well as an incident in 2023 of a software development tool company in which attackers managed to steal access keys and sensitive data after hacking into an engineer's device.
And more than half of the leaks are caused by software errors, such as inserting access keys into published code, increasing the risk of targeting digital supply chains, especially in open-source projects.
And experts called on organizations to list all digital identities that have access to systems, monitor them on an ongoing basis, and determine the validity of credentials, with periodic updates, along with encrypting devices and storing access keys in dedicated and secure tools instead of saving them as exposed text.
And the report stressed that the expansion of the use of artificial intelligence agents will lead to an increase in the number of automated identities in the coming years, which forces institutions to deal with them with the same level of control applied to administrative accounts, by restricting their powers, monitoring their activity, and ensuring that their presence is necessary, to reduce the risk of sophisticated cyber breaches and attacks.
comments