BeyondTrust’s Phantom Labs was founded in 2025 to conduct research and share intelligence pertinent to the company’s security efforts. The recently released Phantom Labs Research Index explores the fruits of the first year of Phantom Labs’ work, including over 400 research ideas and 31 published articles and findings. Of the completed investigations, 75% have been tied to identity or privilege, underlining the importance of identity security in modern environments. Attackers today are far more likely to chase trusted relationships than rely on isolated CVEs for access.
Mapping the Root Causes Behind the Numbers
According to Phantom Labs, more than half of the problems investigated can be traced to six root causes, with the most common being credential and secret exposure at 18%. This is followed by identity relationships and graph exposure (11%), excessive or standing privilege (11%), identity misconfiguration (10%), and lateral movement (6%). The types of issues that feature most prominently in the research underline where risk lies in modern environments, demonstrating where security priorities should shift.
These root causes of security issues are rarely isolated. Many problems stem from two or more causes, and the issues underlying threats are often comorbid and interconnected. Standing privilege and privilege escalation are the most commonly combined causes, and the single cause most likely to show up alongside other factors is credential exposure.
The focus of these research efforts on identity and privilege is a signal of how important these issues are amid the explosive growth of agentic AI and other current technological trends. “Today, service accounts, API keys, machine credentials, automation scripts, AI agents and other Non-Human Identities (NHIs) often outnumber human users by dozens or even hundreds to one,” says Shane Barney, Chief Information Security Officer at Keeper Security, a Chicago-based provider of zero-trust and zero-knowledge cybersecurity software. “As organizations embrace cloud infrastructure, DevOps pipelines, AI and automation, NHIs have become foundational to business operations – and a rapidly expanding attack surface.”
AI Agents Enter the Identity Graph Unsupervised
Research related to AI and LLMs accounted for nearly half of the ideas pursued by Phantom Labs in its first year. This research was distributed across several—often overlapping—subjects, including AI platforms (58%), AI agents and agentic systems (42%), model and data security (12%), prompt injection and jailbreak attempts (9%), and AI-specific privilege escalation (6%).
These numbers are reflective of many organizations’ growing reliance on cloud AI platforms and agentic systems. Agentic AI can authenticate, invoke tools, and inherit permissions in the same way as any other identity, but they are always on and operating at machine speed. These tools simultaneously introduce the risk of the agent itself acting in unsanctioned ways and the risk of threat actors taking advantage of the agent to launch attacks. Compounding the risk, AI tools and agents are rarely monitored and secured as thoroughly as necessary.
The heavy research focus on these topics demonstrates the immense importance of AI governance and protection in modern security efforts. “AI risks have rapidly moved from a watch list item to a front-line security concern, especially when it comes to data security and misuse,” according to Diana Kelley, Chief Information Security Officer at Noma Security, a New York City-based unified AI security and governance platform. “To manage this emerging threat landscape, security teams need a mature, continuous security approach, which includes blue team programs, starting with a full inventory of all AI systems, including agentic components as a baseline for governance and risk management.”
When New Ecosystems Inherit Old Assumptions
In addition to research and published findings, Phantom Labs also works on coordinated disclosures of newly found vulnerabilities. In its first year, Phantom Labs disclosed vulnerabilities in OpenAI Codex and AWS Bedrock AgentCore, working alongside the companies to remediate the flaws and inform the public about them. The AgentCore case showed inherited permissions escalating into broader account access, while the OpenAI Codex case originated from a command injection vulnerability.
Both of these vulnerability disclosures, as well as much of Phantom Labs’ other research, demonstrate the crucial need to reexamine the way that systems handle identity, privilege, and trust. The issues that Phantom Labs researches are not confined to one or two platforms, but systemically embedded in many leading technologies. Across the data set, AWS, Microsoft Entra ID, GitHub, Okta, and Salesforce all surface repeatedly.
What the Index Means for Security Leaders Going Forward
The Phantom Labs Research Index underlines significant trends that defenders and security leaders can use to help inform their prioritization and execution of security efforts going forward. Identity and privilege now sit at the center of nearly every attack path, representing important areas of focus. Visibility into non-human and agentic identities has become a strategic priority in protecting modern systems, and the disclosures already in the pipeline for Phantom Labs’ second year signal that the trend is continuing to accelerate.