Tag

#access-control

10 stories taggedaccess-control.

A corporate AI system interface showing permission levels and access control mechanisms, with an unauthorized command being executed through a permission bypass
AI Security

When AI Does What It's Told, For the Wrong Person

A new attack technique lets outsiders trigger high-privilege actions inside company AI systems without ever logging in. The flaw isn't in the AI model. It's in how these systems decide who is allowed to ask.

4 min read
An IT administrator's desk with multiple monitors displaying permission matrices and access control lists, papers with least-privilege checklists pinned to the
Identity & Access

Five habits that keep file server access from spiralling out of control

A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

4 min read
A corporate network access point with multi-factor authentication confirmation displayed on screen, showing successful login while simultaneously an attacker ga
Identity & Access

Passing the Login Test Does Not Mean You Let In the Right Person

Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

3 min read
A computer screen showing an AI agent's intended actions versus its permitted scope, with visual indicators showing where the agent's behavior deviates from gua
AI Security

Varonis pitches 'intent-based' guardrails for AI agents that stray off task

Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

4 min read
Government office building interior with security team members working at desks with computer screens, sensitive documents and security breach notifications dis
Breaches

UK Government Investments Agency Exposed Data on 51 Officials for 40 Hours

A security failure at the public body that manages taxpayer stakes in companies like Channel 4 and the Post Office left sensitive management records and personal details of more than 50 civil servants sitting openly accessible online for nearly two days.

3 min read
Enterprise security operations center with AI monitoring dashboards displayed across multiple large screens, access control policies and behavioral guardrails v
AI Security

AI Agents Need More Than a Watchful Eye. They Need a Leash.

Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

4 min read
A split-screen visual effect showing rapid AI processing and data streams on one side, and a security team's slower monitoring station on the other, emphasizing
AI Security

Your AI Is Moving Faster Than Your Security Team Can Follow

Boards want CISOs to greenlight AI projects at speed. The tools to track what those AI systems actually touch, and whether they're behaving safely, haven't kept up.

3 min read
Illustration: a modern open-plan office desk
Policy & Regulation

European Workers Trust Their Collaboration Tools. The Numbers Tell a Different Story.

A new survey finds that most IT leaders in the UK, France and Germany feel confident about how securely their teams share information at work. But the same survey shows files staying open too long, consumer apps slipping in through the back door, and fewer than a third of organisations using a secure channel for outside partners.

3 min read
Illustration: A vast server room corridor stretching into the distance, bathed in cool blue light
Identity & Access

AI Agents Need Passports, Not Passwords

Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

3 min read
Illustration: A dense server rack corridor bathed in cold blue and amber light, access panel door slightly ajar
Identity & Access

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed

The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

2 min read
© 2026 Threat Vectr