The Credential Crisis: How Forgotten Identities Became Your Biggest Attack Surface
The security industry spends enormous energy chasing sophisticated threats—nation-state tactics, zero-days, supply chain attacks. But this week's most chilling statistic comes from an unglamorous corner of cybersecurity: unmanaged credentials. According to new data highlighted in research on ghost identities, 68% of cloud breaches in 2024 traced back not to compromised user passwords or phishing links, but to forgotten service accounts and abandoned API keys. Not one person in your organization was watching them. For every human employee on payroll, your infrastructure contains 40 to 50 automated credentials nobody remembers creating.
This forgotten-credential crisis appears across the threat landscape this week, and it reveals a fundamental shift in how attackers are winning. They're not necessarily breaking in smarter—they're finding doors that were left unlocked years ago, then never checked again.
Consider the parallel story unfolding around phishing kits. Tycoon 2FA, once the crown jewel of attacker tooling, has been disrupted, but what's remarkable isn't the platform's downfall—it's that other phishing kits are immediately reusing its tools. Why? Because phishing remains devastatingly effective. It remains effective partly because security teams are drowning in identity management. When your org is struggling to track 40-50 credentials per employee across cloud infrastructure, how much attention are users actually paying to spotting a convincing login prompt? The human security perimeter breaks not because humans are suddenly more gullible, but because they're cognitively overloaded. Attackers exploit credential fatigue.
The same pattern appears in infrastructure we think of as "managed." The Mirai variant Nexcorium is now actively hijacking TBK DVRs and end-of-life TP-Link routers for DDoS botnets, exploiting CVE-2024-3721. These aren't new vulnerabilities or novel attack techniques—they're garden-variety device compromise against hardware that shipped with default credentials, never patched, never inventoried, silently running in server closets and branch offices. Each hijacked DVR is a forgotten credential in physical form.
Meanwhile, the supply chain is reminding us that forgotten or overlooked code carries its own credential-like risk. A critical remote code execution vulnerability in protobuf.js—a JavaScript library for Protocol Buffers—has proof-of-concept exploit code in the wild. Protocol Buffers are Google's serialization format, deeply embedded in countless applications. Protobuf.js is the JavaScript implementation, widely trusted, quietly used in dependencies that your teams never explicitly chose. This is different from a forgotten credential—it's a forgotten component. You didn't create this risk; you inherited it. And if you can't account for where protobuf.js is actually running in your stack, you can't patch it. The vulnerability exists in code you depend on but don't directly control.
On the resilience side, NAKIVO has released v11.2 with enhanced ransomware defenses, faster replication, and support for vSphere 9 and Proxmox VE 9.0. This matters because ransomware operators have learned that if they can't get in through credentials or supply chain, they'll destroy your ability to recover from those compromises. Backup and replication infrastructure has become a first-class target, not an afterthought. The fact that recovery tools are advancing against ransomware suggests the industry is finally treating recovery not as a technical problem but as a strategic defense.
A smaller friction point emerged this week when Microsoft Edge pushed an update that broke right-click paste in Teams. This is a minor incident—a UX regression, not a security breach. But it's worth noting because Teams is now critical infrastructure for many organizations, and even small reliability regressions ripple outward. When the tools your team uses to communicate about security break unexpectedly, you've created another gap where human processes fail.
The broader pattern is clear: our security perimeter has become impossibly large. We're defending against sophisticated attacks at the edge while leaving entire forests of forgotten credentials, unpatched legacy devices, and untracked dependencies wide open in the interior. Attackers aren't working harder—they're just moving through the doors nobody thought to lock.
What this means for your organization: the next 90 days should be ruthlessly focused on visibility, not sophistication. You need to answer three questions: What credentials exist in your environment that you've forgotten about? What devices and code components are running that nobody explicitly manages? And for each of these, do you have a path to either retire it or actively defend it? The cyber insurance surveys will tell you next year whether this works. For now, the data is unambiguous—forgotten assets are the path of least resistance, and our attackers have found the way.
Key Takeaways
- Unmanaged credentials, not phishing sophistication, drove 68% of cloud breaches in 2024. Service accounts and API keys without human oversight have become the primary attack vector. Inventory and monitor all non-human identities, not just users.
- Supply chain and library vulnerabilities now require active tracking of dependencies you never directly chose. The protobuf.js RCE demonstrates that critical code can hide in layers of dependencies. Implement real-time visibility into your full stack, including transitive dependencies.
- Legacy devices and end-of-life infrastructure remain actively exploited as botnet fodder. TBK DVRs and EoL routers compromised for DDoS aren't edge cases—they represent entire categories of forgotten infrastructure. Asset discovery and retirement must be a standing operations priority.
- Ransomware operators now target recovery infrastructure directly. Backup and replication systems are no longer safe by obscurity. Treat backup defense with the same rigor as data protection itself.
The Wire is HackWire's daily editorial briefing, published every morning.