Topic

non-human identity

Every THE D[AI]LY BRIEF article on non-human identity — enterprise AI analysis, benchmarks, vendor comparisons, and ROI frameworks for technology and business leaders. Updated as new coverage publishes.

prompt injection

An Eval Sandbox Gave Up Its Keys. Your Gateway Holds Yours.

Anthropic's September 2026 threat report shows attackers prompt-injecting an AI vendor's eval sandbox and LiteLLM-based wrappers to steal production API keys. Any harness or gateway that reads untrusted text while holding a key is a credential store — split, scope and cap those keys.

September 12, 2026 · 11 min read
AA26-251A

CISA Named 6 Distillers. Your Agent Fleet Fits the Spec.

The NSA, CISA and FBI advisory AA26-251A tells AI providers to flag accounts by 24/7 usage, instant maximum throughput and cache-optimised traffic — an exact description of a production agent fleet. Its recommended mitigation is an undisclosed model downgrade, engineered to defeat quality measurement.

September 8, 2026 · 13 min read
acqui-hire

Adobe Took Rilo's Team. Its Slack Token Never Expires.

Adobe licensed Rilo's technology and hired its six-person team; Rilo shuts down. But Rilo was a free-tier agent platform wired into 100+ systems, and the OAuth grants it holds in your Slack, Salesforce and Gmail outlive the company that issued them.

September 2, 2026 · 13 min read
Claude Tag

Claude Reads the Whole Channel Now. Invites Are IAM.

Anthropic's August 13 Claude Tag update replaced the per-message classifier with full-channel context. The agent's read scope is now the channel's whole conversation, the member list is the control that governs it, and Anthropic's own docs now say there is no per-action log of who asked.

August 29, 2026 · 15 min read
agent identity

Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs

Entra Agent ID and Okta for AI Agents issue agent credentials. SailPoint Agentic Fabric governs identities it never issues. Which one you need is decided by where your agents already authenticate — and Microsoft is the only vendor of the three that publishes a price.

August 25, 2026 · 23 min read
AI agent security

88% Had AI Agent Breaches. 82% Think They're Protected.

Five independent research teams surveying 6,650+ enterprise leaders arrived at the same conclusion: the AI agent security crisis is measured, quantified, and widely ignored. AvePoint found 88.4% of organizations had AI agent security incidents. The Economist Enterprise study pushed it to 98%. Yet 82% of executives believe their policies protect them. Here's the confidence gap assessment and governance maturity model every CISO needs this quarter.

July 1, 2026 · 16 min read
non-human identity

9 in 10 Enterprises Breached Through Identity No One Manages

Machine identities outnumber humans 109:1 in the average enterprise, yet 57% of that identity estate is invisible to existing IAM tools. Palo Alto Networks surveyed 2,900 cybersecurity decision-makers and found 9 out of 10 organizations experienced identity-related breaches in the past year. AI agents are making the crisis exponentially worse — they discover and exploit ungoverned credential paths faster than any human attacker. Here's the maturity assessment and 90-day roadmap every CISO needs before Q4 agent deployments.

June 30, 2026 · 15 min read
SaaS security

One Credential, 195 Breached Companies: The Klue OAuth Attack

A four-year-old prototype credential at competitive intelligence vendor Klue gave attackers access to OAuth tokens for 195 customer organizations — including Huntress, Recorded Future, HackerOne, LastPass, Tanium, Jamf, Snyk, and OneTrust. The third major Salesforce OAuth supply chain attack in twelve months, the Klue breach exposes a structural blind spot in enterprise SaaS security: non-human identities with persistent, broad API access that no one is monitoring. SaaS integration risk assessment matrix and supply chain incident response playbook inside.

June 29, 2026 · 16 min read