OAuth stories
Identity-led attacks are speeding up intrusions, with LevelBlue finding business email compromise accounted for 45 per cent of incidents in Q2 2026.
Security teams must now track AI agents and machine accounts as well as staff, as BeyondTrust expands Pathfinder to cover privileged access.
Enterprise security teams face fresh oversight burdens as Reco joins OpenAI's partner network to monitor agent access and permissions.
Email fraud is now the top incident type, accounting for 45% of cases as attackers bypass multi-factor authentication with stolen credentials.
Corporate travellers at hotels and conference centres were quietly sent to fake Microsoft 365 pages after attackers took over guest Wi-Fi gateways.
Security teams face higher breach costs as ThreatDown expands visibility over unsanctioned AI tools and machine accounts in one console.
Enterprise teams can now switch on controls for AI agents and APIs faster, with Salt Security bundling 100 pre-built policies into its Policy Hub.
Account takeovers are becoming harder to stop as attackers use real-time code theft and fake login pages to bypass Microsoft 365 MFA.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
Free workshop sandboxes should make it easier for developers to try AWS training without a personal account, credit card or cleanup.
Enterprises can now buy and register third-party AI agents through Google Cloud Marketplace for use inside Gemini Enterprise.
Enterprise AI deployments may be exposing sensitive data through overlooked connector permissions, according to a new governance framework from Vivek Kumar.
Enterprise security teams are being pushed to track what AI agents can access and do across apps, identities and workflows before data is exposed.
The expansion gives IT teams central control over AI agent permissions, reducing risky static keys and easing reviews as workplace use widens.
Trusted third-party access has let attackers quietly pull large volumes of Salesforce records from enterprise systems via a Klue integration.
More than half of Vercel deployments are now triggered by coding agents, as monthly AI token traffic has jumped tenfold.
The tie-up adds tighter access checks as firms deploy AI agents and browser tools more widely, amid rising identity attacks.
Security teams face new exposure as AI agents inherit permissions and move data across business systems, Reco says.
Ransomware attacks spread through vendor systems and AI-aided tactics, leaving 7,551 publicly disclosed victims in the latest 12-month period.
Businesses can now let AI agents update Salesforce records and run tasks through Airbyte's new OpenAI Marketplace listing.