< ciso
brief />
Tag Banner

All news with #machine identity tag

15 articles

Improving SPIRE Security and Resiliency on AWS

🔒 This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more →

Spain Reports First Agentic AI Personal Data Breach

🛡️ Spain’s data protection agency (AEPD) disclosed the country’s first agentic AI-powered personal data breach after an AI agent using a known language model scanned files, logged in, searched for vulnerabilities, and modified personal data and invoices. The AEPD said the agent was used to chain together attack phases, implying deliberate misuse by a threat actor rather than a rogue model. Officials call for AI risks to be included in risk analyses and for machine-speed incident response and stronger identity and credential protections.
read more →

Microsoft issues workaround for Windows domain login bug

🔒 Microsoft provided a temporary workaround after September 2026 security updates caused Windows 11 devices to reject valid domain credentials. The flaw is tied to the Machine Identity Isolation feature entering enforcement mode following updates KB5124008 and KB5124012, which breaks domain trust on systems not using Windows Server 2025 DFL. Administrators are advised to disable Machine Identity Isolation via the same channel it was enabled (Group Policy, Intune, or registry) and then restart and repair the secure channel. Microsoft is preventing enforcement in a future update while working on a permanent fix.
read more →

Google Cloud unveils M4N VMs for I/O‑heavy workloads

🚀 Google Cloud has launched the M4N machine series in Compute Engine, designed for I/O-intensive, high-memory workloads and now generally available. Built on 5th Gen Intel® Xeon® Scalable processors and Google’s Titanium offload architecture, M4N delivers up to 6TB RAM, 25 GiB/s aggregate host storage throughput, and up to 1 million IOPS with Hyperdisk Extreme. The family targets mission-critical databases, generative AI data layers, healthcare ERP, and real-time analytics while promising >20% TCO reduction for Oracle workloads.
read more →

SPIFFE/SPIRE Identity Spoofing in Kubernetes

🔒 This Unit 42 report demonstrates how an attacker with root on a compromised Kubernetes node can abuse the SPIFFE/SPIRE machine identity system to impersonate co‑located workloads and harvest SVIDs. The research shows selector spoofing by manipulating cgroup and process metadata so the SPIRE agent issues another workload's identity. The authors provide an open‑source tool, Spooffe, to test and validate exposure and recommend hardening nodes, restricting root access, and minimizing privileged containers to reduce risk.
read more →

Non-Human Identities Now Primary Enterprise Risk

🔍 The SpyCloud 2026 Identity Threat Report finds non-human identities—AI agents, service accounts, API keys, and tokens—are now the leading path attackers use into enterprises. Despite 95% of organizations believing they have visibility into AI and machine identity exposures, only 36% actively monitor them. The survey of 750 cybersecurity leaders highlights gaps in governance, session monitoring, and third-party remediation, and shows automated continuous monitoring materially reduces incident impact. SpyCloud recommends pairing continuous exposure monitoring with automated remediation to lower event rates and costs.
read more →

AWS adds per-record confidence to Entity Resolution

🔍 AWS Entity Resolution now supplies per-record confidence scores for ML-based matching, replacing the prior group-level score that treated all records identically. This update lets each resolved record carry its own confidence metric, enabling differentiated activation thresholds for automated merges and lower-threshold inclusion while preserving audit-ready evidence. Existing schemas remain compatible as the RecordConfidenceLevel column now reflects per-record values, and the feature is available in all Regions where the service runs.
read more →

Synthetic Machine Identity Fraud and Emerging Risks

🔒 Synthetic identity fraud for machines involves attackers fabricating service accounts or credentials rather than stealing existing ones. These fabricated NHIs blend real environmental attributes with fake data to appear legitimate, evading detection because no human owner flags misuse. Techniques include rogue service accounts, DCShadow-style fake domain authorities, and shadow credentials implanted into existing objects. Defenses focus on ownership, secrets rotation, least privilege, and continuous behavioral verification.
read more →

Governing the growing ghost workforce risk

🛡️ Enterprises are facing an invisible workforce: non-human identities (bots, service accounts, API keys, tokens, certificates) that now often outnumber humans. These ghost identities authenticate constantly across environments and, when unmanaged, accumulate privileges and risks. The industry has seen incidents where forgotten or third-party machine identities enabled widespread breaches, and a looming 2026 certificate-expiration wave threatens cascading outages. Organisations must prioritise governance—discovering NHIs, assigning ownership, auditing privileges, and addressing imminent certificate expirations—before tool selection.
read more →

SageMaker Studio Adds Flexible Training Plan Reservations

🚀 Amazon SageMaker Studio IDEs, including JupyterLab and Code Editor, now support GPU capacity reservations via SageMaker Flexible Training Plans (FTP), offering predictable access to high-performance resources and up to 65% cost savings versus On‑Demand. FTP provides a self-serve procurement flow to select instance type, reservation length, and start date. Studio apps can be launched using the purchased plan from the Instance dropdown, with automatic provisioning and proactive expiration notifications to protect work.
read more →

Palo Alto Launches Idira to Secure AI and Identities

🔒 Palo Alto Networks has unveiled Idira, an identity security platform designed to protect human users, machine identities, and autonomous AI agents by applying dynamic privilege controls across all identity types. The platform leverages Palo Alto’s integration of CyberArk and continuously discovers and enriches identities across SaaS, cloud, and developer environments. Idira elevates privileges only when required and revokes them immediately, aiming to close blind spots left by legacy IAM and PAM systems. Analysts say it targets gaps in offerings such as Auth0 and SailPoint but does not eliminate the need for layered security.
read more →

RSA Conference 2026: Six Takeaways for Security Leaders

🔒 RSA Conference 2026 made clear that AI dominated every conversation, reframing priorities for CISOs and security teams. Sessions and hallway discussions emphasized securing the AI stack, managing rampant shadow AI usage, and governing machine or non-human identities. Speakers warned that AI accelerates both attacks and defensive response, while capital and workforce dynamics are shifting rapidly.
read more →

Ephemeral Infrastructure Paradox: Strengthen Identity

🔒 Modern cloud environments create vast numbers of short-lived machine identities that outnumber humans and often remain unmanaged. The author argues that traditional, ticket-driven identity governance is inadequate for ephemeral workloads and supply-chain tooling, exposing organizations to “zombie” service accounts and credential theft. The recommended response is a shift to cryptographic workload identity (e.g., SPIFFE and workload attestation), elimination of long-lived static credentials via short-lived tokens and OIDC Federation, and automated entitlement pruning using CIEM to restore least-privilege without slowing engineering velocity.
read more →

Securing Every Identity in the AI-Driven Enterprise

🔐 CyberArk is joining Palo Alto Networks to elevate identity security as a core platform pillar for cloud, automation and AI-driven environments. The post argues identity is now the primary attack vector: machine identities outnumber humans by more than 80:1 and 87% of organizations experienced multiple identity-centric breaches in the past year. It calls for continuous visibility, dynamic privilege controls and unified governance to secure human, machine and AI agents and reduce opportunities for lateral movement.
read more →

AWS Launches EC2 Instance Attestation for Trusted Instances

🔒 AWS announced general availability of EC2 instance attestation in September 2025, enabling customers to cryptographically verify that only trusted software and configurations run on EC2 instances, including those with AI chips and GPUs. The feature uses NitroTPM and Attestable AMIs to create and compare cryptographic measurements of AMI contents. It integrates with AWS KMS so key operations can be restricted to instances that pass attestation. EC2 instance attestation is available in all AWS Commercial Regions, including AWS GovCloud (US).
read more →