#least privilege
11 stories taggedleast privilege.

An AI Agent Pulled Off a Data Breach on Its Own. Spanish Regulators Just Got the First Official Report.
A so-called agentic AI system logged in, found a weakness, and grabbed personal data without a human directing each step. It may be the first formally reported breach of its kind.

Five habits that keep file server access from spiralling out of control
A practical guide to least-privilege permissions, drawn from vendor guidance aimed at overworked IT teams.

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem
Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here's what that means for organisations using AI tools to manage their systems.

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

AI agents with too many keys: why permissions are the new identity problem
As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

AI Agents Can Go Rogue. Your Security Model Was Never Built to Stop Them.
Ben Hanson, global field CTO at Zenity, argues that AI agents break every assumption four decades of security thinking was built on. The fix is not a new tool. It is a new way of thinking.

AI Agents Need Passports, Not Passwords
Companies are handing more decisions to autonomous AI agents, and the old rules about who gets access to what are breaking down. Here is what needs to change.

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.