New NIST and CISA guidance on securing identity tokens fails to fully address the unique authorisation challenges and risks introduced by autonomous AI agents.
A new security flaw called "workflow identity hijacking" allows unauthenticated users to trigger privileged AI workflows and access sensitive enterprise systems.