#IAM
36 stories taggedIAM · page 2 of 3.

The AI helpers your staff installed without telling IT
Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

When your AI helper has admin rights: the new ransomware fast lane
Enterprise AI assistants with over-broad permissions can turn a routine break-in into a company-wide ransomware event in minutes, Acronis warns.

AI Agents Are Making Security Playbooks Obsolete. Identity Is the Fix.
Security teams built their rules for humans clicking buttons. AI agents click a thousand buttons a second, and the old playbook cannot keep up.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
AI tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams haven't caught up.

Cloud Security Professionals Gather Virtually to Tackle Shared Threats
A summit for security teams wrestling with cloud and data protection brings together practitioners and vendors, here is why these conversations matter to anyone whose data lives online.

Your Vendors Are a Risk You Cannot Ignore. Here Is How Boards Should Own It.
Most companies review their suppliers and tick the boxes. Far fewer can say how much financial damage a vendor failure would actually cost them. That gap is the problem.

Hackers Broke Into an AI Gateway and Found a Door to Everything
A cryptomining attack on an Amazon cloud server was almost certainly the least damaging thing the criminals could have done. Security researchers say AI gateways are becoming one of the most overlooked entry points in enterprise computing.

Cryptomining attack on an AI gateway reveals a much bigger cloud security problem
Hackers broke into an Amazon cloud server acting as a doorway to AI services, planted mining software, and probed for wider access. The real worry is how much power these AI gateways hold.

AI Agents Need Passports, Not Passwords
Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

Seven Cyber Risk Assessment Mistakes That Give Security Leaders False Confidence
Organisations tick boxes, skip awkward corners of their networks, and confuse passing an audit with being secure. Here is what actually goes wrong.

One Researcher, 14 Flaws, Millions of Indians at Risk
A young independent security researcher found gaping holes in Indian government portals, including an admin panel left wide open to the entire internet. The government fixed everything within three weeks.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents, and a poisoned repo is all it takes to start the chain.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

Guardian Agents and the Identity Layer That Doesn't Exist Yet
Autonomous agents are inheriting human permissions at machine speed. The IAM stack wasn't built for this, and the governance gap is growing.