Tag: identity
-
The Governance Gaps Holding Back Enterprise Agentic Networks
Enterprise AI is moving from individual assistants to interconnected networks of autonomous agents. That creates a new governance challenge: knowing which agent acted, why it acted, what permissions it had and who authorized it. Identity, runtime policy, delegation controls and auditability are quickly becoming foundational AI security requirements. First seen on securityboulevard.com Jump to article:…
-
Cryptographic Attestation Is the Missing Layer for Autonomous AI Security
As autonomous AI agents gain access to sensitive systems, cryptographic attestation provides verifiable proof of identity, actions and access”, strengthening incident response, zero trust and regulatory compliance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cryptographic-attestation-is-the-missing-layer-for-autonomous-ai-security/
-
Identity at AI speed: What to look forward to at Ping YOUniverse 2026
First seen on scworld.com Jump to article: www.scworld.com/resource/identity-at-ai-speed-what-to-look-forward-to-at-ping-youniverse-2026
-
OpenAI Workload Identity Federation: Aembit Brings Secretless Access to the OpenAI API
3 min readAembit already covers a lot of ground when it comes to securing AI workload access. For OpenAI’s ChatGPT, workloads can authenticate to the ChatGPT API using static API key injection, with the Aembit proxy handling direct access transparently. Today, we’re extending that coverage with the introduction of the OpenAI Workload Identity Federation Credential…
-
Detecting NTDS.dit extraction attempts on domain controllers
NTDS.dit is the Active Directory database on a domain controller. It holds directory objects, password hashes, and other identity data that make it a high-value target. If an attacker can copy or extract it, they may be able to work offline against credentials and move from one compromised account to broader domain access. For that……
-
‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
-
KI-Agenten erzwingen ein neues Identitätsmodell für Unternehmen
Autonome KI-Agenten stellen klassische Identity Security infrage. Unternehmen benötigen kurzlebige Identitäten, Kontextkontrolle und klare Governance. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-agenten-erzwingen-ein-neues-identitaetsmodell-fuer-unternehmen/a46081/
-
Horizon3 Raises $250M to Prove What Attackers Can Exploit
Startup Says Autonomous Testing Can Demonstrate Business Impact Without Disruption. San Francisco-based Horizon3 raised a $250 million Series E funding round at a $2 billion valuation to expand autonomous testing across infrastructure, identity and web applications as AI gives attackers new ways to discover, exploit and traverse enterprise weaknesses at machine speed. First seen on…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Cogent Launches VR-1 Cyber Reasoning Model for Enterprise Attack Paths
Cogent Security has introduced Cogent VR-1, a frontier reasoning model trained to investigate enterprise environments and prove whether multi-step attack paths are reachable. The model starts with a foothold and an objective, then maps the surrounding environment and connects weaknesses across systems. Cogent said VR-1 can work across cloud infrastructure, identity systems and internal tools,..…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
On-Behalf-Of vs. Service Account: Choosing an Agent Identity Model
A decision guide for AI agent identity: when to delegate with RFC 8693, when to use a client-credentials service account, and the spec rules that make the choice for you. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/on-behalf-of-vs-service-account-choosing-an-agent-identity-model/
-
1Password Adds Privileged Access Controls for Human and AI Identities
1Password has launched Privileged Access, extending its Unified Access platform into privileged access management with controls designed to remove standing permissions from human and AI identities. The July 28 launch came ahead of Black Hat USA 2026, where identity security and AI-agent controls are major themes. 1Password said Privileged Access provisions permissions when they are..…
-
Why CTOs Must Get Hands-On With Enterprise AI
1Password’s Nancy Wang on AI Builders, Agent Identity and Secure Adoption. AI is changing how software is built, who gets to build it and how enterprises must manage identity. 1Password CTO Nancy Wang explains why technology leaders need hands-on experience with AI and why autonomous agents require security guardrails of their own. First seen on…
-
Why Passkeys Are Closing the Account Takeover Gap
HealthEquity’s Ajit Gaddam on Passwordless Security, Fraud Signals, Cyber Defense. Passwords remain a weak point in account security, especially when attackers can buy stolen credentials and exploit recovery workflows. Ajit Gaddam explains how passkeys, biometrics and device signals can strengthen identity assurance while reducing login friction. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/passkeys-are-closing-account-takeover-gap-a-32442
-
ElringKlinger modernisiert Identitäts- und Zugriffsmanagement mit Omada
ElringKlinger modernisiert sein Identitäts- und Zugriffsmanagement mit Omada Identity und ersetzt SAP IDM durch eine zentrale Governance-Plattform. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/elringklinger-modernisiert-identitaets-und-zugriffsmanagement-mit-omada/a46035/
-
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at…
-
Surf AI Adds Claude Compliance Integration and Exposure Reduction Operations
Surf AI has added an integration with Claude’s Compliance API and made Exposure Reduction Operations generally available, extending its platform to govern AI model connectivity alongside identity, cloud and SaaS exposures. The Claude integration pulls activity logs from an organization’s Claude environment, maps connection and access paths to an accountable owner in Surf’s Context Graph,..…
-
ElringKlinger modernisiert Identity- und Access-Management mit Omada Identity
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/identity-access-management-modernisierung
-
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake. First seen on therecord.media Jump to article: therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka
-
Aembit Adds Workload Identity Federation Support for the Claude API
5 min readToday, we’re announcing the Aembit Claude Workload Identity Federation Credential Provider, the latest addition to Aembit’s growing Claude support. Aembit already covers a lot of ground with Claude: workloads can authenticate to the Claude API using static API key injection, Claude Web and the Claude App are supported as Client Workloads, direct API…
-
Fake Open VSX Extensions Harvest Private Repo and CI Data
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-vsx-evil-twin-extensions-git/
-
JetStream Launches AI Kill Switch for Individual Agents
JetStream Security has launched an AI Kill Switch that can shut down a single compromised or malfunctioning AI agent without affecting other AI operations. The control is part of JetStream’s AI governance platform. The company said it combines the person who invoked an action, the agent identity carrying it out, the system’s stated intent and..…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection. First seen on hackread.com Jump to article: hackread.com/brazil-health-surveillance-database-exposed-records/

