#least privilege
11 stories taggedleast privilege.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

AI agents with too many keys: why permissions are the new identity problem
As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face
During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

AI Agents Can Go Rogue. Your Security Model Was Never Built to Stop Them.
A cybersecurity expert warns that AI agents, software programs that make decisions and take actions on their own, break every assumption that four decades of security thinking was built on. The fix is not a new tool. It is a new way of thinking.

AI Agents Need Passports, Not Passwords
As companies hand more decisions to autonomous AI agents, the old rules about who gets access to what are breaking down. Here is what needs to change, and why it matters to everyone.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

Treat the Model Like a Threat: Why AI Agent Security Needs a Systems Overhaul
A paper from researchers at Google and two US universities argues that prompt-level defences and alignment tuning are structurally inadequate for securing autonomous AI agents — and that enterprises should start treating the model itself as an untrusted component.