< ciso
brief />
Tag Banner

All news with #identity security tag

194 articles · page 2 of 10

IAM Identity Center adds multi‑Region directory replication

🔁 IAM Identity Center now replicates identities and entitlements from the primary AWS Region to additional Regions when using the Identity Center directory as the identity source. This extends prior multi‑Region support for organization instances that used external identity providers to those using the Identity Center directory, improving resilience and enabling deployment closer to users and for data residency. The feature requires a multi‑Region customer managed KMS key and is available in the 17 enabled‑by‑default commercial Regions; standard KMS charges apply.
read more →

Best Buy scales secure AI access with federation

🔒 Best Buy eliminated service account key hassles by adopting Google Cloud's Workforce Identity Federation to let developers use their existing Microsoft Entra ID credentials for secure access to BigQuery and other cloud services. This syncless approach removes the need to synchronize user records into Cloud Identity, reduces credential management and attack surface, and delivers auditable, user-level access. The change is largely invisible to developers while simplifying operations for security and platform teams.
read more →

Amazon EKS adds PrivateLink for OIDC endpoints

🔒 Amazon EKS now supports AWS PrivateLink for the cluster OIDC discovery and JWKS endpoint, allowing access to the OIDC endpoint used by IAM Roles for Service Accounts (IRSA) privately from your VPC without internet egress. Tools such as eksctl, Terraform, or custom token validators can reach the discovery document and JWKS via an interface VPC endpoint for the com.amazonaws..oidc-eks service. This ensures correct DNS resolution when the EKS management VPC endpoint uses private DNS. The feature is available in all Regions where Amazon EKS is offered at standard AWS PrivateLink pricing.
read more →

Visibility Alone Fails AI Agent Security Controls

🔎 AI agent discovery is necessary but insufficient; security must move from visibility to enforcement. Organizations find agents across SaaS, cloud, developer tools, and internal systems, but inventory without context leaves risk unmanaged. Effective controls require correlating ownership, identities, intent, access, usage, and lifecycle to create purpose-driven, platform-agnostic rules. The goal is an identity-centric control plane that can discover, understand, and enforce agent behavior.
read more →

AI agent identities create a new enterprise attack surface

🛡️ The Sophos AI Security 2026 Report warns that rapid enterprise adoption of AI tools has created a growing attack surface as AI agents and assistants gain privileged access to systems. Threat actors are targeting OAuth tokens, service credentials and exposed AI infrastructure because governance has not kept pace. The report urges treating AI agents like human users, enforcing least privilege, manual verification for new access and setting alerts for suspicious AI behavior.
read more →

Post-Breakup Digital Security Steps to Take Now

🔒 After a breakup, shared digital ties like accounts, subscriptions, and devices can leave you vulnerable if not properly separated. Review active sessions, update passwords and recovery options, and remove your ex from trusted devices and family-sharing settings. Revoke access to smart home devices, unlink payment methods, and cancel or recreate shared subscriptions. Use password managers, privacy tools, and support services to reclaim control and protect your safety.
read more →

Microsoft Secure Future Initiative July 2026 Report

🔒 This progress report outlines Microsoft’s Secure Future Initiative (SFI) two-year effort to strengthen security foundations, apply AI for proactive defense, and prepare for future challenges such as post-quantum risks. It highlights layered controls—identity, access governance, segmentation, and secure engineering defaults—paired with cultural and governance measures to make protections durable. The report also shares lessons, practical guidance, and metrics of organizational adoption.
read more →

Verification Step Emerges as New ATO Attack Surface

🛡️ Passkeys and passwordless flows are reducing credential stuffing, but attackers now target identity verification and recovery paths such as magic links, step-up flows, and re-enrollment. Generative AI has made impersonation and synthetic media widespread, increasing fraudulent verification attempts. Defenders must adopt biometric liveness, risk-based re-verification, intent binding, and network-effect signals to stay ahead as regulations and threats evolve.
read more →

Agentic AI Exposes Zero Trust Blind Spots

🤖 Stephen Wilson of HashiCorp describes agentic AI as “really smart kindergartners” — capable of execution but lacking judgment. This mismatch strains traditional zero trust models that authenticate humans and grant privileges gradually, because agents can be created and destroyed rapidly. Organizations often respond by lowering controls, risking incidents such as accidental deletion of production data. Wilson argues this will force necessary long-term improvements like zero standing privilege and dynamic credentials while keeping humans "on the loop."
read more →

Governing Identity for Agentic AI Operations

🛡️ Existing security controls weren’t built for autonomous AI agents, and static credentials and standing privileges are insufficient. Organizations must define agentic identity, secure agent-to-agent communication, adopt dynamic secrets management, enforce least privilege for delegated workflows, and unify workforce identity. Governance across the identity lifecycle is essential to ensure auditable, revocable, and context-aware access for agents.
read more →

Operationalizing agentic AI: From assistants to operators

🤖 Stephen Wilson of HashiCorp explains how enterprise AI is evolving from human-assisted tools to autonomous agents and operators, and why governance must mature accordingly. He describes three adoption patterns—AI as assistant, AI as agent, and AI as operator—and details the increasing needs for identity, access controls, auditability, and accuracy at each stage. As organizations grant agents more autonomy, security controls must expand from user-level boundaries to team and organizational governance.
read more →

SMB Cyber Readiness: Prioritize the Fundamentals

🔒 AI is reshaping attacker toolkits, but familiar failures—phishing, unpatched vulnerabilities, poor monitoring and weak passwords—remain the primary causes of incidents for SMBs. ESET telemetry and research show AI mainly amplifies these risks rather than replacing them with pervasive, real-time AI malware. Practical mitigations like patch management, identity protection, MFA, password managers and MDR services remain the most effective ways to improve readiness and resilience.
read more →

Identity lifecycle challenges posed by AI agents

🔒 This article explains how traditional identity lifecycle management — built around HR-driven joiner, mover, and leaver events — fails to govern AI agents. It describes how agents are created outside HR and IGA workflows, arrive with embedded credentials, and expand access dynamically at runtime. The piece highlights gaps in provisioning, access reviews, and offboarding when agents proliferate across parallel instances and orchestration layers.
read more →

Claude Apps Gateway for Google Cloud announced

🔒 Anthropic’s Claude Apps Gateway is a self-hosted intermediary that centralizes identity, policy, telemetry, spend controls, and routing between local Claude Code clients and Google Cloud. It replaces per-developer credentials with OIDC-based sessions, enforces RBAC server-side via gateway.yaml, and attributes metrics to verified user sessions. Deploy as a stateless container on Cloud Run (or GKE) with Cloud SQL and Secret Manager for state and secrets.
read more →

Palo Alto Networks Defines Identity Security Future

🔒 Palo Alto Networks announces Idira™, its next-generation identity security platform, following the acquisition of CyberArk to position identity as a core control plane for AI-driven enterprises. The platform treats every identity—human, machine and AI agent—as privileged, offering real-time discovery, just-in-time privilege and continuous governance. Partners are urged to adopt new advisory and delivery models to help customers reduce fragmentation and secure hybrid, cloud-native, and AI-enabled environments. The move aligns with customer demand for integrated, AI-powered security and supports partner enablement through the NextWave program.
read more →

IAM Identity Center: Customer Managed App Account Access

🔐 IAM Identity Center now lets customer managed applications programmatically discover user-assigned AWS accounts and roles and retrieve temporary credentials for account access. If your application authenticates users via an external identity provider (IdP), you can configure that IdP as a trusted token issuer and enable AWS account access so users who already signed in through the IdP can obtain credentials without re-authenticating. Administrators must explicitly enable this for each customer managed application, and only management account or delegated administrators can grant the capability, ensuring centralized governance. The feature is available across all commercial, GovCloud (US), and China Regions.
read more →

Guardian Agents: The Next Layer of Identity

🛡️ This guide examines how agentic AI shifted enterprise identity risks and why existing IAM controls fall short. It explains how AI agents inherit human permissions, traverse systems at machine speed, and create an expanding population of autonomous identities often deployed without security review. The piece outlines the guardian agent concept: a purpose-built runtime control layer that inventories agents, baselines behavior, detects anomalies, and enforces least-privilege at execution time to close the governance gap.
read more →

One Million Passports Exposed in Data Leak

🔐 A database containing nearly one million passport records from multiple countries was leaked online. The incident highlights how high-value credentials like passports can be compromised when reused within lower-security systems; in this case, an ID verification service used by cannabis dispensaries was breached. The exposure demonstrates the cascading risk when sensitive identity documents are trusted by ancillary services with weaker protections.
read more →

AI-Driven Identity Security: Microsoft Entra Updates

🔒 AI is accelerating cyberattacks, increasing speed and scale across the attack chain while identity remains a primary entry point. Microsoft highlights integrated visibility and response through Microsoft Entra and Microsoft Defender, including a unified identity risk score and an updated Entra ID Protection experience. New features aim to reduce fragmentation, enable least-privilege response roles, and automate policy optimization to help teams prevent, detect, and respond faster.
read more →

Estonia Proposes Government IDs for AI Agents

🛡️ The Estonian AI Council proposes government-backed digital identities for AI agents to define delegated powers and responsibilities. Prime Minister Kristen Michal emphasized that clear attribution, rights, and accountability are essential as AI increasingly acts on behalf of people and organizations. The ID could specify permissions such as data viewing, document editing, or making payments with defined limits. Estonia aims to leverage its digital ID leadership and become the first country to formalize agent identities.
read more →