Tag

#least privilege

11 stories taggedleast privilege.

A computer terminal showing automated system commands executing in real-time with data extraction logs, while security monitoring alerts flash red in the backgr
AI Security

An AI Agent Pulled Off a Data Breach on Its Own. Spanish Regulators Just Got the First Official Report.

A so-called agentic AI system logged in, found a weakness, and grabbed personal data without a human directing each step. It may be the first formally reported breach of its kind.

3 min read
An IT administrator's desk with multiple monitors displaying permission matrices and access control lists, papers with least-privilege checklists pinned to the
Identity & Access

Five habits that keep file server access from spiralling out of control

A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

4 min read
An AI agent interface window showing a vague command being interpreted with improvised system-level actions executing, permission structure breakdown visualized
AI Security

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem

Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

4 min read
An AI agent interface on a monitor showing a domain management dashboard, a firewall log excerpt visible in a window behind it with one blocked request highligh
AI Security

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company

Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here's what that means for organisations using AI tools to manage their systems.

5 min read
An enterprise office environment with employees using AI-assisted software tools at their workstations, network visualizations showing automated agents making u
AI Security

AI Agents Are Breaking Into Your Own Systems, With Your Permission

The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

4 min read
AI security research lab with multiple screens displaying autonomous AI agent behavior monitoring, security boundaries and containment protocols visualized, res
AI Security

Why Locking Down What AI Agents Can Do Is Not Enough

A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

4 min read
An AI agent with multiple oversized keys floating around it, each granting access to different company systems, with security researchers observing from the sid
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
Enterprise security operations center with AI monitoring dashboards displayed across multiple large screens, access control policies and behavioral guardrails v
AI Security

AI Agents Need More Than a Watchful Eye. They Need a Leash.

Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

4 min read
A network operations center with multiple monitors displaying complex data flows and algorithmic processes, with warning indicators flashing across screens as a
AI Security

AI Agents Can Go Rogue. Your Security Model Was Never Built to Stop Them.

Ben Hanson, global field CTO at Zenity, argues that AI agents break every assumption four decades of security thinking was built on. The fix is not a new tool. It is a new way of thinking.

3 min read
Illustration: A vast server room corridor stretching into the distance, bathed in cool blue light
Identity & Access

AI Agents Need Passports, Not Passwords

Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

3 min read
Illustration: A dense server rack corridor bathed in cold blue and amber light, access panel door slightly ajar
Identity & Access

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed

The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

2 min read
© 2026 Threat Vectr