Analysis · Sep 29, 2026
The credentials nobody owns: five September incidents and the inventory that missed them
A spraying campaign that only worked on functional accounts, a service principal secret in a GitHub issue, an email address that commits code, a public database key with no authorization behind it, and a leaver's token kept alive on purpose. None needed a new exploit. All of them were credentials no person was accountable for.