Identity sprawl, often called secrets sprawl, describes the unmanaged proliferation of digital credentials like API keys and tokens across an organization's IT environment. This widespread distribution creates a massive and expanded attack surface, as non-human identities (NHIs) often possess overprivileged access and their secrets are frequently exposed in code or scattered systems. Uncontrolled NHIs, particularly with the rapid growth of AI agents, pose critical security risks, leading to potential breaches, operational disruptions, and compliance failures if not properly managed.
Secrets Sprawl: https://podcast.cisomarketplace.com/e/the-ai-paradox-unmasking-the-secrets-sprawl-in-2025
Sponsors:
https://devsecops.vibehack.dev
Version: 20241125
No comments yet. Be the first to say something!