Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Application risk intelligence and identity controls: what changed in July 2026?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Exploitation windows are shrinking to hours, supply chain compromise is shifting toward CI/CD credentials and developer tooling, and identity abuse now underpins much of modern ransomware and extortion activity, according to Veracode. Preventive controls, contextual prioritisation, and machine identity governance matter more than detection alone.

NHIMG editorial — based on content published by Veracode: CISO Executive Briefing: Application Risk Intelligence for July 2026

By the numbers:

Questions worth separating out

Q: What breaks when identity is embedded into CI/CD without governance?

A: Configuration changes can propagate quickly, but so can mistakes, stale privileges, and inconsistent exceptions.

Q: Why do service accounts and vendor access increase ransomware risk?

A: Service accounts and vendor identities often have broad, persistent, and poorly reviewed access, which makes them ideal for lateral movement after initial compromise.

Q: How do security teams know whether contextual prioritisation is working?

A: Look for shorter remediation times on externally exposed and credential-bearing systems, fewer high-risk findings waiting across multiple cycles, and a clear drop in unowned critical items.

Practitioner guidance

  • Inventory pipeline and registry identities Map every CI/CD account, maintainer account, signing identity, token, and package-manager credential used to build or promote software.
  • Enforce contextual prioritisation for exploitable flaws Rank remediation by internet exposure, exploit activity, privilege path, and whether an affected component is reachable from identity-rich workflows such as build runners or package mirrors.
  • Treat AI agent credentials as governed identities Assign owners, scopes, expiration rules, and logging to any AI system that can call tools, read secrets, or move data between systems.

What's in the full report

Veracode's full briefing covers the operational detail this post intentionally leaves for the source:

  • Specific package firewall policies for npm, PyPI, Maven, RubyGems, NuGet, Cargo, and Golang ecosystems
  • Risk Manager and Fix workflow details for prioritising and remediating high-risk findings
  • Pipeline integration guidance for GitHub, Azure DevOps, Jenkins, and CLI-based policy gates
  • Action-oriented recommendations for board reporting, SLAs, and AI-related code controls

👉 Read Veracode's July 2026 application risk intelligence briefing →

Application risk intelligence and identity controls: what changed in July 2026?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Identity is now the primary control plane of application risk. The briefing’s strongest signal is not the number of vulnerabilities but the way attackers keep winning through trusted identities embedded in build, release, and runtime workflows. Service accounts, tokens, and maintainer credentials are no longer supporting controls, they are attack objectives. That aligns with OWASP NHI thinking and NIST CSF access governance, and it means application security and identity governance can no longer operate as separate programmes.

A question worth separating out:

Q: Who is accountable when an AI agent uses delegated access incorrectly?

A: Accountability should follow the delegated authority chain, not stop at the agent label. The relevant owners are the teams responsible for the human identity, the service identity, the workflow, and the policy that allowed the action path. If those responsibilities are not explicit, incident review will be incomplete and remediation will focus on the wrong layer.

👉 Read our full editorial: Application risk intelligence now hinges on identity and supply chain



   
ReplyQuote
Share: