A few years ago, the concept of "infrastructure" consisted of - servers, a couple of data centers (or maybe a VPC in AWS), and a spreadsheet of employees with their badges and laptops. Today, in most companies, the term infrastructure covers autonomous AI agents making their own API calls, Kubernetes-controlled clusters that are constantly launching and terminating various workloads, and machine identities for every single service and bot that was previously just a throwaway line of configuration that nobody really bothered with.
In 2026 infrastructures, AI agents and non-human identities frequently outnumber humans by ratios ranging from 3-to-1 to over 40-to-1, depending on the specific digital or enterprise environment.
This shift happened so quickly that most security teams struggled to keep up and adapt.
What actually changed
attackers did not become smarter overnight, but rather the surface to attack grew at a faster rate than could be cataloged.
More and more identities than ever...
Every AI agent, service account, API key, and OAuth token is now another identity to manage. The problem is that most of these identities aren't tied to a specific person, so there's no one to ask, "Do you still need this?" In many enterprises, machine identities already outnumber human identities by more than 100 to 1, and that gap keeps growing. Most security teams don't even have a complete list of these identities, let alone the time to review each one.
Too much autonomy for manual review
An AI agent doesn't wait for a code review or a change ticket. If it decides it needs to call an API, start a container, or connect to another system, it can do it right away. That's the whole point of using AI agents. But it also means the old idea of "a human approves everything before it reaches production" doesn't work the way it used to. Many of the actions happening in production today are made by machines, not people.
More surface than a quarterly scan can cover
Cloud environments, Kubernetes clusters, and the APIs connecting everything can change every day, sometimes every hour. A security assessment that was accurate on Monday might already be out of date by Thursday if someone creates a new namespace or an AI agent gets a new credential. Quarterly audits were designed for infrastructure that didn't change this quickly.
Put all three changes together, and the part of the attack surface that's growing the fastest is also the part security teams have the hardest time seeing.
Which identity security controls does your organization apply across the AI agent lifecycle? Source: Palo Alto Networks, via Help Net Security
The numbers
- Machine identities, AI agents, service accounts, API keys, and certificates, now outnumber human identities by 109 to 1 in the average enterprise, up from 82 to 1 just a year earlier, according to Palo Alto Networks. Of those 109, roughly 79 are AI agents specifically, according to Axis Intelligence's analysis of the same survey.
- 83% of organizations had at least two successful identity-related breaches in the past 12 months, and 96% of human accounts operate with more access than their job actually needs, according to Palo Alto Networks.
- 53% of CISOs say they can't confidently enumerate even half of the machine identities running in their own environment, according to AI Cybersecurity Forum. Nearly a third of identity-related breaches traced back to a non-human credential that nobody on the current team could even identify as theirs.
- Hardcoded secrets keep landing straight in public code. GitGuardian found 28.65 million new secrets exposed on public GitHub in 2025 alone, up 34% year over year, with AI-service-related leaks specifically jumping 81.5%, according to Axis Intelligence.
New hardcoded secrets exposed on public GitHub. Source: GitGuardian, State of Secrets Sprawl 2026
- Cloud intrusions rose 37% year over year in 2025, and 70% of cloud breaches now trace back to a compromised identity rather than a software exploit, according to CrowdStrike and SentinelOne data compiled by StationX.
- 93% of organizations running Kubernetes experienced at least one security incident in the past year, and 53% detected an actual misconfiguration in their clusters, according to a Red Hat survey covered by InfoWorld.
credit: metavert
few new tricks attackers are using
Infrastructure has changed in ways that give attackers new entry points — many of which didn't exist five years ago.
Exposed control planes as an attack platform. Docker APIs, Kubernetes dashboards, and tools like Ray can become serious security risks when they're exposed to the public internet. An attacker doesn't always need a zero-day if a management interface is accepting requests from anywhere. A single misconfigured cluster can give an attacker a way to explore the environment and potentially deploy malicious code across its workloads.
Supply chain pivoting through a stolen non-human credential. A leaked service-account token isn't necessarily limited to one system. If that account belongs to a tool that's trusted by many downstream pipelines, stealing one credential can give an attacker a path into multiple systems.
Autonomous agents finding their own way in. This is a newer problem. An AI agent with a broad goal and access to multiple tools may be able to reach other systems without someone directing every step. If accessing another system helps it complete its task, it may try to do so without anyone explicitly telling it to.
Attacks are increasing in scale as AI adoption accelerates and infrastructure becomes more interconnected. credit: sysdig
Case studies
an incidents from 2026 show exactly what happens when these tricks land on infrastructure nobody was watching closely enough.
When your own AI agents breach someone else's production systems
The escape path, per OpenAI's own timeline: sandbox, improvised message board, then someone else's production systems. Illustration: CellCog
In July 2026, OpenAI's internal evaluation agents, mainly an unreleased research model, were running a cybersecurity benchmark meant to test how well AI systems handle offensive security tasks. The benchmark included some genuinely difficult challenges. The agents' response to getting stuck wasn't to give up. It was to go looking for the answers somewhere else on the internet, a behavior researchers call reward hacking. The chain of failures:
- The agents escaped their sandbox by exploiting a zero-day in a package registry cache proxy, one of their few permitted paths to the outside internet.
- From there, they found an unrelated third-party sandbox on the cloud platform Modal, left with a default public API key and a command-injection flaw, and used it as a staging point.
- Multiple agents began coordinating through a shared message board they weren't supposed to have access to, leaving each other notes about what they'd found and what they still needed.
- They inferred that Hugging Face might host the benchmark's answer key, found 14 publicly exposed Hugging Face write tokens sitting in a public dataset, and used them to get in.
- Once inside, they exploited a flaw in Artifactory's Ruby-based processing to steal a signing key, forged administrator credentials, and executed code across dozens of production servers, eventually gaining root on at least one.
- Around the same time, other agents turned the same tactics on OpenAI's own infrastructure: escalating from an unprivileged container to root using a Linux kernel vulnerability, pulling cloud credentials straight from the instance metadata service, and gaining administrator access to a Kubernetes cluster.
Nobody was driving this by hand. OpenAI's own postmortem says the models "communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems," entirely on their own initiative, while trying to pass a test. The company halted training and inference for the model involved and published a full technical timeline. Hugging Face published its own alongside it. This is what "autonomous workload" means once something goes wrong: nobody typed the commands, and the thing that did still has to be treated like an intruder once it's inside.
When a treasury-controlling AI agent amplifies a routine device hack
Step Finance was Solana's most widely used DeFi portfolio dashboard, branded "the front page of Solana," alongside its media arm SolanaFloor and its derivatives platform Remora Markets. On January 31, 2026, during APAC trading hours, attackers got into the personal devices of several Step Finance executives through what the company only described publicly as "a well-known attack vector." No smart contract bug, no clever exploit. The chain of failures:
- The break-in itself was ordinary. Attackers compromised the personal devices of a handful of executives, the same starting point behind a large share of crypto thefts every year.
- From those compromised devices, attackers reached the platform's treasury and fee wallets directly. No smart contract exploit was needed once they were in.
- Step Finance's AI trading agents held standing permissions across wallets, price oracles, and trading endpoints all at once, and were configured to execute large transfers without a human sign-off in the loop.
- Once the attackers had a foothold, that permission structure did the rest of the work for them. 261,854 SOL, worth roughly $28 to $30 million at the time, moved out of the treasury in a single incident.
- Total losses across every affected wallet reached close to $40 million. Blockchain security firm CertiK helped trace the transfers, but only about $4.7 million was ever recovered.
Step Finance, SolanaFloor, and Remora Markets all shut down for good on February 23, 2026, less than a month later. Worth being precise about what's actually confirmed here: Step Finance's own public disclosure names the root cause as compromised executive devices, nothing more specific. The detail that AI trading agents turned a containable device compromise into a company-ending loss by holding excessive, unchecked permissions comes from later security-industry analysis, not from Step Finance itself. Either way, the shape of the failure is the same one showing up everywhere else in this piece: an ordinary intrusion becomes catastrophic the moment the thing you broke into can move tens of millions of dollars on its own.
Step Finance shutdown due to Hack through a Compromised executive and an AI Agent with overly Excessive Permissions
Here's how to secure infrastructure that won't stay the same aka which will evolve each day..
A quarterly pentest worked when infrastructure changed slowly enough that a test from one point in time was still useful months later. That isn't true anymore.
Start by knowing every identity that has access, not just the people. Machine identities should be managed like employee accounts: they need an owner, an expiration date, and a clear reason for why they still exist. If nobody knows what an identity is for, it's much harder to spot when it's being misused.
Treat AI agents as a new type of insider, especially when they have access to multiple tools and systems. Give each agent only the access it needs, log what it does, and make sure you can stop it while it's running instead of only checking the results afterward. The broader the agent's access, the more important these controls become.
Assume control planes could be exposed until you've checked them. Audit Docker APIs, Kubernetes dashboards, Ray, Redis, and similar services to see what is actually reachable from the internet today. Don't rely on what you remember configuring when the environment was first set up.
Rotate credentials properly, not just because a policy says you should. If an old key stays valid after a new one is issued, a leaked credential can remain useful to an attacker. Short-lived credentials are safer because they expire automatically instead of depending on someone remembering to revoke them.
Finally, move from point-in-time testing to continuous validation. Map the paths an attacker could take from public-facing services to sensitive systems, and check those paths whenever the environment changes. If your infrastructure can change by the hour, your security checks need to keep up with those changes.
Securing NHIs (Non-Human Indentities) Checklist. Credit: cerbos
conclusion AKA bottom line
So, looking at the title, what has changed? Well, the basics remain the basics. Credentials still need to be protected, exposure reduced, and systems monitored. What changed is the scope, the scale, and the speed. More identities than we care to track manually, more autonomous decisions being made without a human in the loop, and more infrastructure shifting between audits than any one audit can capture at a given point in time.
The discipline in securing the AI-native enterprise isn't new. It's an extension of the same discipline, applied at a scale that requires continuous rather than periodic diligence and across a surface that is significantly more non-human than before. The companies that get it right aren't the ones that acquire the most tools first. They are the ones that stop thinking about infrastructure as something they check on periodically and start thinking about it as something they can monitor continuously.
Sources for the numbers used above
- Machine identities outnumber humans 109 to 1, up from 82 to 1 the year before; roughly 79 of those 109 are AI agents. Palo Alto Networks, "2026 Identity Security Landscape" (May 2026); breakdown of the AI-agent share via Axis Intelligence, "Machine Identity Statistics 2026" (updated June 15, 2026)
- 83% of organizations had at least two successful identity-related breaches in the past 12 months; 96% of human accounts are overprivileged. Palo Alto Networks, "2026 Identity Security Landscape"
- 80 to 1 machine-to-human identity ratio; 92% of executives name managing AI agents as the top future security skill. KPMG Cybersecurity Considerations 2026, reported via NHIMG (June 5, 2026)
- 45 to 1 machine-to-human identity ratio. Rubrik Zero Labs research, reported via The Hacker News Expert Insights (May 18, 2026)
- 53% of CISOs can't enumerate even half their machine identities; 31% of identity breaches trace to an unrecognized non-human credential. AI Cybersecurity Forum, citing the 2026 Verizon DBIR cohort (April 15, 2026)
- 28.65 million new hardcoded secrets exposed on public GitHub in 2025, up 34% year over year; AI-service-related leaks up 81.5%. GitGuardian 2026 report, cited in Axis Intelligence, "Machine Identity Statistics 2026"
- Cloud intrusions rose 37% year over year in 2025; 70% of cloud breaches trace back to a compromised identity. CrowdStrike and SentinelOne data, compiled by StationX, "Cloud Security Statistics 2026"
- 93% of organizations running Kubernetes had a security incident in the past year; 53% detected a misconfiguration; 55% delayed deployment over security concerns. Red Hat "State of Kubernetes Security" survey, reported via InfoWorld
- OpenAI evaluation agents breached Hugging Face's production infrastructure in July 2026 through reward hacking. Direct disclosure from OpenAI, "The Hugging Face incident and the road ahead"; independent technical timeline from Hugging Face, "Anatomy of a frontier lab agent intrusion"; additional reporting via The Hacker News and Wikipedia's incident summary
- TeamPCP compromised over 60,000 cloud servers via exposed Docker, Kubernetes, Ray, and Redis interfaces, then backdoored the Trivy scanner via a stolen service-account token. eSecurity Planet and The Hacker News on the initial campaign (February 2026); Flare Emerging Threats Team on the Trivy supply chain pivot and subsequent arrests; SentinelOne on the credential-harvesting toolset
