Non-Human Identity Management: Why Ephemeral Credentials Are Replacing Static API Keys
Service accounts, CI/CD runners, workload certificates and AI-agent principals form a sprawl traditional joiner-mover-leaver programs never governed.
Author
Threat intelligence editor
Focuses on cloud identity, incident response, and exploitation trends.
Service accounts, CI/CD runners, workload certificates and AI-agent principals form a sprawl traditional joiner-mover-leaver programs never governed.
*A conceptual view of Jenkins as the high-privilege control plane of the software factory—and of plugins as the supply-chain links that can break it.*
The chain moves from Safari RCE through sandbox escape to kernel read/write, exfiltrates data within minutes, then cleans up and exits with no user interaction.
Microsoft and CISA confirmed exploitation on 14 July 2026 and shipped same-day patches. SharePoint Online is unaffected; self-hosted farms need action now.
Roughly triple June's previous record, the release is led by CVE-2026-50518, an unauthenticated Windows DHCP Server RCE rated Exploitation More Likely.
Patched in the record July 2026 Patch Tuesday, the flaw puts finance, supply-chain and operations systems at risk wherever ERP login endpoints remain reachable.
Golden SAML still threatens hybrid identity via AD FS token-signing keys. Learn how to harden DKM access, detect key theft, and lock down federation servers.
CISA set a July 17 remediation deadline, but patching alone leaves an already-compromised appliance in place — credential rotation and hunting are mandatory.