#access-control
10 stories taggedaccess-control.

When AI Does What It's Told, For the Wrong Person
A new attack technique lets outsiders trigger high-privilege actions inside company AI systems without ever logging in. The flaw isn't in the AI model. It's in how these systems decide who is allowed to ask.

Five habits that keep file server access from spiralling out of control
A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

Passing the Login Test Does Not Mean You Let In the Right Person
Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

UK Government Investments Agency Exposed Data on 51 Officials for 40 Hours
A security failure at the public body that manages taxpayer stakes in companies like Channel 4 and the Post Office left sensitive management records and personal details of more than 50 civil servants sitting openly accessible online for nearly two days.

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

Your AI Is Moving Faster Than Your Security Team Can Follow
Boards want CISOs to greenlight AI projects at speed. The tools to track what those AI systems actually touch, and whether they're behaving safely, haven't kept up.

European Workers Trust Their Collaboration Tools. The Numbers Tell a Different Story.
A new survey finds that most IT leaders in the UK, France and Germany feel confident about how securely their teams share information at work. But the same survey shows files staying open too long, consumer apps slipping in through the back door, and fewer than a third of organisations using a secure channel for outside partners.

AI Agents Need Passports, Not Passwords
Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.