CISO Middle East Issue 03 | Page 29

B
IDENTITIES

BeyondTrust research finds 75 % of cyberattacks linked to identity and privilege exposure

eyondTrust has released the

B

Phantom Labs Research Index, an annual analysis of the factors driving today’ s cyberattacks based on offensive security research conducted by the team. The report found that attackers are increasingly exploiting trusted relationships between users, applications, machine identities and AI agents rather than relying solely on isolated software vulnerabilities.
Analysing more than 400 research projects over the past year, Phantom Labs found that 75 % of completed investigations involved identity or privilege in some way. When sorted by root cause, six problems accounted for more than half of the findings, including credential and secret exposure at 18 %, identity relationships and graph exposure at 11 %, excessive or standing privilege at 11 %, identity misconfiguration at 10 % and lateral movement at 6 %.
These root causes rarely appeared in isolation. Standing privilege and privilege escalation appeared together most frequently, while credential exposure was the issue most likely to compound with another problem.
“ As organisations connect human, machine, and AI agent identities across dispersed environments, attackers don’ t need to find a new vulnerability. They’ re looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today,” said Jonathan Johnson, Senior Manager, Research at BeyondTrust.“ That’ s exactly what we saw across our research this year: three out of four projects traced back to identity or privilege in some form, and standing privilege and privilege escalation showed up together more often than any other combination we tracked.”
AI agents become enterprise identities
AI and LLM security was Phantom Labs’ single largest research focus in its first year, accounting for half of all projects. The work spanned cloud AI platforms at 58 %, AI agents and agentic systems at 42 %, model and data security at 12 %, prompt injection and jailbreak techniques at 9 % and AI-specific privilege escalation at 6 %, with many projects covering more than one category.
As organisations connect human, machine, and AI agent identities across dispersed environments, attackers don’ t need to find a new vulnerability.
Research highlights risks across AI and cloud platforms
Beyond identity relationship mapping, Phantom Labs’ original vulnerability research included coordinated disclosures across AI platforms, including OpenAI Codex and AWS Bedrock AgentCore. According to BeyondTrust, the findings demonstrate how emerging AI ecosystems continue to inherit fundamental security assumptions around identity, privilege and trust.
The pattern was not confined to AI. Across all research conducted in the first year, AWS appeared in 85 mentions, Microsoft Entra ID and Azure in 57, GitHub in 40, Okta in 33 and Salesforce in 33. BeyondTrust said this indicates that similar identity assumptions extend across cloud, identity provider, DevOps and SaaS ecosystems.
Jonathan Johnson, Senior Manager, Research at BeyondTrust
As organisations deploy AI agents across cloud, SaaS and internal workflows, BeyondTrust found that these agents increasingly authenticate to systems, invoke tools, access data and inherit permissions much like other enterprise identities, often with significantly less oversight.
Phantom Labs’ research has also been incorporated into BeyondTrust products, including Identity Security Insights, as well as published research and coordinated disclosures. The company said this enables findings from offensive security research to be translated into protections that defenders can act on before privileges are exploited.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 29