
Latest
Three Frontier Labs, Two Weeks: Rogue AI Agents Are Real
OpenAI, Anthropic, and Meta each confirmed an agent incident against a real target in three weeks. The labs are right that it was a test. The capability is not.
Read the article
Tag
All topics →Machine and non-human identity: securing the agents, services, and workloads that now authenticate far more often than humans do.
41 stories, newest first.

Latest
OpenAI, Anthropic, and Meta each confirmed an agent incident against a real target in three weeks. The labs are right that it was a test. The capability is not.
Read the article
Self-propagating instructions can spread through ordinary agent memory. Isolated agents with conflicting goals wrote malware to sabotage each other.

CrowdStrike clocks 29-minute breakout times and an 89% surge in AI-augmented attacks. Here is the five-phase framework I use with CISOs to close that gap, with budget splits and a board script.

Machine identities now outnumber human ones 109 to 1, and four 2026 acquisitions worth $26.6B prove vaults can't keep up. What ephemeral secrets and workload identity replace them with.

A leaked static key is a disaster; a five-minute token is mostly a shrug. Here is the credential lifecycle that gets AI agents from 24-hour tokens to ephemeral ones.

Shadow AI is an employee pasting into ChatGPT. A shadow agent holds real credentials and acts on its own. That is a different, and bigger, problem.

IAM decides who gets in the door. PAM controls the keys that can rewire the building. Here is the real difference, where they converge in 2026, and why your AI agents need both.

Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.

The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days.

Hugging Face detected the intrusion on July 16. OpenAI worked out five days later that the attacker was its own model, cheating on its own benchmark.

Agents can already prove who they are. What no standard has cleanly solved is passing scoped authority down a multi-hop chain across organizations. Here is the real state of agent identity in 2026, minus the blockchain hype.

Machine identities now outnumber humans by 45 to 1 or more, and every AI agent widens the gap. Here is what an identity orchestration layer is, in plain terms, and how to build one that governs humans, workloads, and agents from a single control plane.

The leading non-human identity (NHI) management tools for 2026, compared by job: discovery and posture, secrets management, machine identity, and workload identity.

A poisoned LiteLLM package led to 4TB stolen from Mercor, the AI training startup serving Meta, OpenAI, and Anthropic. Class action lawsuits filed.

Google I/O 2026 shipped an entire agent stack: Gemini 3.5 Flash, Antigravity 2.0, WebMCP, Gemini Spark, and Agent Payments Protocol. What it means for builders.

Vercel breached after attacker compromised Context.ai, hijacked an employee's Google Workspace via OAuth, and accessed customer API keys and environment

Three AI framework attacks in one week expose how classic vulnerabilities are hiding in AI's foundational plumbing, putting millions of deployments at risk.

An employee saw the CFO on video. Heard colleagues speaking. Authorized $25M in transfers. Every person was an AI-generated deepfake.

AI didn't just create new attack surfaces. It fundamentally changed who, and what, is requesting access in your environment.

Clawdbot is the viral AI assistant everyone's installing, but giving AI agents full system access raises critical security questions.

A Comprehensive Guide for Investment Bankers, Private Equity, and Venture Capital Professionals

Authentication requirements block 75-80% of enterprise deals, costing B2B SaaS companies millions annually.
Looking for Delinea PAM alternatives? Discover 10 powerful privileged access management solutions offering advanced security features, seamless

Your IAM strategy is obsolete. Organizations now manage 96 machine identities per human, AI agents make autonomous decisions at scale, and 45% of
Explore the top 10 Azure AD alternatives for 2025. Compare Okta, JumpCloud, OneLogin, Ping Identity, and more with detailed analysis of SSO, MFA, identity
Explore the top 10 Identity Lifecycle Management solutions for 2025. Compare Apono, Microsoft Entra ID, SailPoint, Okta, and more with detailed analysis

While you perfected human identity management, machines quietly took over your infrastructure.

Static API keys scattered across repositories create exponential security debt as AI scales. The solution? Credentials that live for minutes, not months.

Traditional role-based access control assumes predictable behavior, but AI agents exhibit emergent behaviors no human anticipated.

Navigate the $25.96B+ IAM market with confidence. This expert guide compares 29 leading identity solutions, from Okta to emerging players like HYPR.

Most companies are creating massive security blind spots by forcing AI agents into human identity systems.

This deal represents the maturation of the identity market. The days of pure-play identity vendors competing primarily on features are ending.

Confused by the growing identity management landscape? This comprehensive guide breaks down every IAM category, from traditional workforce identity to

Confused by IAM, CIAM, and IDaaS? This guide breaks down the key differences to help you choose the right identity solution for your business.
The identity industry faces its biggest shift yet: machines now outnumber humans 90:1 in digital systems.

Machines talk to machines without human intervention. But how do you ensure these automated conversations remain secure?

Explore the evolution of Single Sign-On for autonomous AI agents, focusing on securing non-human identities and the future of agentic automation security.

This in-depth research investigates Single Sign-On (SSO) and its application to both human users and non-human identities.

As AI agents dominate workflows, traditional SSO struggles with machine-speed authentication.

AI agents need to prove both their own identity and that a human authorized the action. Here is the three-token delegation architecture that answers both, and the security layers around it.

As artificial intelligence evolves, the concept of "identity" extends beyond humans. This article delves into the technical intricacies of non-human