Persistent AI agents, acting as "digital colleagues," are challenging traditional identity and access management. This "third wave" of AI demands dedicated identities, scoped permissions, and robust lifecycle controls to prevent new security risks.
Vulnerabilities in the Amazon Bedrock AgentCore Python SDK could enable command execution within AI sandboxes, potentially exposing AWS credentials.
An estimated 77% of global organisations experienced Microsoft 365 governance incidents over the past year, exacerbated by the rapid adoption of AI tools.
Threat actors have compromised MemTensor packages on npm and PyPI to deploy the sckit credential stealer, targeting sensitive cloud and developer secrets.
Security researchers have identified a 'confused deputy' vulnerability in Google Kubernetes Config Connector that could allow an attacker to seize control of an entire Google Cloud organisation.