SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Summary
Non-human identities (NHIs), which are AI agents, service accounts, API keys, and authentication tokens that connect to internal systems, have become attackers' most common entry point into organizations, with 31% of breaches starting this way. Despite 95% of organizations believing they monitor NHI exposures, only 36% actually do, creating a dangerous gap where these identities often stay compromised for months because nobody actively manages them. The report found that 68% of organizations experienced identity-based attacks in the survey period, averaging eight events each.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
First tracked: September 9, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 75%