#IAM
42 stories taggedIAM.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

DataBahn Raises $40 Million to Put AI in Charge of Enterprise Data Pipelines
The Texas startup wants companies to stop moving every byte of data everywhere and start routing only what actually matters, in real time.

AI agents are approving transactions and nobody is watching
A new report finds most companies have handed financial controls to AI systems they cannot audit, trace, or investigate in real time.

AI agents with too many keys: why permissions are the new identity problem
As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

The AI helpers your staff installed without telling IT
Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

When your AI helper has admin rights: the new ransomware fast lane
Enterprise AI assistants with over-broad permissions can turn a routine break-in into a company-wide ransomware event in minutes, Acronis warns.

AI Agents Are Making Security Playbooks Obsolete. Identity Is the Fix.
Security teams built their rules for humans clicking buttons. AI agents click a thousand buttons a second, and the old playbook cannot keep up.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Cloud Security Professionals Gather Virtually to Tackle Shared Threats
A summit for security teams wrestling with cloud and data protection brings together practitioners and vendors, here is why these conversations matter to anyone whose data lives online.

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.
Most companies review their suppliers and tick the boxes. Far fewer can actually say how much financial damage a vendor failure would cause them. That gap is the problem.

Hackers Broke Into an AI Gateway and Found a Door to Everything
A cryptomining attack on an Amazon cloud server was almost certainly the least damaging thing the criminals could have done. Security researchers say AI gateways are becoming one of the most overlooked entry points in enterprise computing.

Cryptomining attack on an AI gateway reveals a much bigger cloud security problem
Hackers broke into an Amazon cloud server acting as a doorway to AI services, planted mining software, and probed for wider access. The real worry is how much power these AI gateways hold.