SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
BeyondTrust warns identity risks drive most attacks

BeyondTrust warns identity risks drive most attacks

Tue, 4th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

BeyondTrust has released its Phantom Labs Research Index, which found that 75% of more than 400 offensive security investigations involved identity or privilege.

The findings suggest a shift in how attackers gain access. Rather than relying only on standalone software flaws, they are increasingly exploiting identity relationships between users, applications, machine identities and AI agents.

According to Phantom Labs, BeyondTrust's research team, six root causes accounted for more than half of all issues identified during the review period. Credential and secret exposure made up 18% of findings, followed by identity relationships and graph exposure at 11%, excessive or standing privilege at 11%, identity misconfiguration at 10%, and lateral movement at 6%.

These weaknesses rarely appeared in isolation. Standing privilege and privilege escalation appeared together more often than any other combination, while credential exposure was the issue most likely to overlap with another problem.

Identity focus

The research suggests many current security problems stem from how access is granted, inherited and trusted across cloud, software-as-a-service and on-premises environments. In practice, attackers can move through linked systems by exploiting permissions and relationships that are already in place.

Jonathan Johnson, Senior Manager, Research, BeyondTrust, described that pattern in the latest review.

"As organisations connect human, machine, and AI agent identities across dispersed environments, attackers don't need to find a new vulnerability. They're looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today," Johnson said.

"That's exactly what we saw across our research this year: three out of four projects traced back to identity or privilege in some form, and standing privilege and privilege escalation showed up together more often than any other combination we tracked."

AI agent risks

AI and large language model security was Phantom Labs' single biggest area of work in its first year, accounting for half of all projects covered by the index. Within that total, the work spanned cloud AI platforms, AI agents and agentic systems, model and data security, prompt injection and jailbreak techniques, and AI-specific privilege escalation.

The team said 58% of that AI-related work involved cloud AI platforms, while 42% covered AI agents and agentic systems. Model and data security accounted for 12%, prompt injection and jailbreak techniques for 9%, and AI-specific privilege escalation for 6%, with some projects spanning more than one category.

That emphasis reflects a broader concern in corporate technology environments. As businesses roll out AI agents into internal workflows and external services, those systems are increasingly treated like digital workers that authenticate to applications, call tools, access information and operate with inherited permissions.

The report argues that this makes AI agents part of the enterprise identity estate. It also suggests they often receive less scrutiny than human users or conventional service accounts, even when granted comparable levels of access.

Platforms exposed

The research also covered coordinated vulnerability disclosures involving OpenAI Codex and AWS Bedrock AgentCore. Those cases, BeyondTrust said, showed how newer AI ecosystems can still reflect long-established security assumptions around identity, privilege and trust.

Outside AI-specific work, several technology platforms appeared frequently across the broader body of research. AWS was mentioned 85 times, followed by Microsoft Entra ID and Azure on 57 occasions, GitHub on 40, and both Okta and Salesforce on 33.

The distribution suggests the issues were not limited to one segment of the market. Cloud infrastructure, identity providers, developer platforms and business software all featured in the team's work, indicating that the same structural weaknesses can surface across different layers of enterprise technology.

BeyondTrust said the research has informed parts of its product development, including work linked to Identity Security Insights, as well as published research and coordinated disclosures. It described that process as a way to feed offensive security findings back into defensive controls before privileged access is abused.

Overall, the index suggests modern attacks are often built on chains of trust rather than a single exploitable bug. In that environment, security teams may need to pay closer attention to how identities, permissions and relationships combine across systems, especially as AI agents become another class of user inside the enterprise.

AWS, Microsoft Entra ID and Azure, GitHub, Okta and Salesforce were the platforms that surfaced most often across the research reviewed.