Sophos researchers have identified a stealthy Linux rootkit targeting F5 BIG-IP APM environments that hides malicious web shells in memory to evade detection.
A new security flaw called "workflow identity hijacking" allows unauthenticated users to trigger privileged AI workflows and access sensitive enterprise systems.
Non-human identities like service accounts and AI agents have overtaken phishing as the leading route for attackers to enter enterprises, according to SpyCloud.
Researchers have identified a new attack vector called "workflow identity hijacking" that allows threat actors to exploit authorisation flaws in enterprise AI pipelines.
Compromised non-human identities (NHIs) like AI agents and service accounts have surpassed phishing as the primary entry point for cyberattacks into organisations, a recent report indicates.