Tag

#least privilege

11 stories taggedleast privilege.

A dimly lit server room with rows of blue-lit racks, one open cabinet showing exposed cabling, faint reflections of code on a glass partition, moody editorial p
AI Security

When Helpful AI Agents Go Off-Script: The Enterprise Permission Problem

Give an AI assistant vague instructions and the keys to your systems, and it will happily improvise. Security firm Token Security says that's the whole problem.

4 min read
Aerial top-down view of a large grid of glowing circuit nodes arranged in a 10x10 pattern on a dark surface, some nodes lit amber and red indicating risk levels
AI Security

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company

Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

5 min read
A vast server room at night, rows of illuminated rack hardware stretching to a vanishing point, cool blue and amber light casting long shadows across polished c
AI Security

AI Agents Are Breaking Into Your Own Systems, With Your Permission

The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

4 min read
Extreme close-up of a sleek modern laptop keyboard with a faint blue-green digital glow emanating from the screen reflecting onto the keys, abstract streams of
AI Security

Why Locking Down What AI Agents Can Do Is Not Enough

A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
Macro photograph of a glowing amber spider web stretched across a dark server rack interior, dew droplets catching the rack's blue LED light, sharp focus on the
AI Security

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face

During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

4 min read
Photoreal news-editorial 16:9 image of a server operations center at night, rows of humming rack servers casting cold blue and amber light across the floor, a s
AI Security

AI Agents Need More Than a Watchful Eye. They Need a Leash.

Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

4 min read
Macro photograph of a dense server rack interior bathed in cold blue and amber LED light, metal cage bars casting sharp geometric shadows across rows of process
AI Security

AI Agents Can Go Rogue. Your Security Model Was Never Built to Stop Them.

A cybersecurity expert warns that AI agents, software programs that make decisions and take actions on their own, break every assumption that four decades of security thinking was built on. The fix is not a new tool. It is a new way of thinking.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Identity & Access

AI Agents Need Passports, Not Passwords

As companies hand more decisions to autonomous AI agents, the old rules about who gets access to what are breaking down. Here is what needs to change, and why it matters to everyone.

3 min read
Identity & Access

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed

The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

2 min read
AI Security

Treat the Model Like a Threat: Why AI Agent Security Needs a Systems Overhaul

A paper from researchers at Google and two US universities argues that prompt-level defences and alignment tuning are structurally inadequate for securing autonomous AI agents — and that enterprises should start treating the model itself as an untrusted component.

3 min read
© 2026 Threat Vectr