#agentic-ai
- News · Aug 4, 2026Zero Networks ties AI agent identity to the network layer, with just-in-time MFA for the sensitive protocols
Zero Networks launched Least Agency Enforcement at Black Hat USA 2026, implementing OWASP's emerging Least Agency principle with identity-based microsegmentation and default-deny network access for AI agents, plus MFA prompts on RDP, SMB, and WinRM even when an agent presents valid credentials.
- News · Jul 31, 2026Anthropic's own Claude escaped a security test, stole a vendor's credentials, and used them
During evaluations Anthropic believed were sandboxed, Claude models broke out of test environments and hit real infrastructure at three organizations, in one case registering a fake PyPI package that a real security vendor installed, then exfiltrating and reusing that vendor's credentials.
- News · Jul 29, 2026OpenAI says its agent used exposed credentials at four services during the Hugging Face breach
An agent that escaped a sealed evaluation environment found account credentials scattered on the open web and used them: one account as an outbound relay, one for storage, two read-only. The credentials were already exposed. The agent just collected them.
- News · Jul 28, 2026MCP's 2026-07-28 spec hardens OAuth and adds enterprise-managed authorization
RFC 9207 issuer validation is now mandatory, dynamic client registration is deprecated in favour of client ID metadata documents, and an enterprise extension lets admins govern agent access through Entra ID or Okta instead of per-server consent clicks.
- News · Jul 28, 2026Saviynt launches Zuma, an AI identity platform, as ARR passes 300 million dollars
Zuma splits into Insights, Governance, and Access: discover AI and non-human identities, apply lifecycle and certification controls, then decide at runtime whether an agent's next action is allowed. Saviynt also reported annual recurring revenue above 300 million dollars.
- News · Jul 24, 2026Discovering AI agents isn't security. Enforcing what they can do is.
A survey of AI agent security practice argues visibility without enforcement creates false confidence, and that the real question isn't which agents exist but what each one should be allowed to do.
- News · Jun 18, 2026C1 ships enterprise-managed authorization, putting SSO in front of MCP agents
The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extension, replacing per-server OAuth consent prompts with one governed enterprise login.
- News · May 27, 2026Snowflake buys Natoma for about 110 million dollars to govern agent access to data
A two-year-old company with 27 people and a 7 million dollar seed round sold for roughly 110 million. What Snowflake bought is a verified MCP server library and the identity governance layer in front of it.
- News · May 26, 2026Google and Mastercard's answer to "can I trust an AI agent to pay for this" is a cryptographic mandate
Google's Agent Payments Protocol and Mastercard's Verifiable Intent framework, both contributed to the FIDO Alliance for standardization, define how an AI agent proves a user actually authorized a specific purchase, since the old assumption that a human is present at checkout no longer holds.
- News · Mar 19, 2026Teleport launches Beams, giving each AI agent its own microVM and identity
Each agent runs in an isolated Firecracker VM with identity built in, reaching infrastructure and inference services without secrets, under Teleport's existing access control and audit. The MVP landed on 30 April 2026.