Secrets Management stories
DTEX warns Telegram & WhatsApp AI agents risk exfiltration
3 days ago
#
virtualisation
#
physical security
#
dlp
DTEX warns that AI agents controlled via Telegram and WhatsApp can quietly access files, expose credentials and exfiltrate data from endpoints.
Claude Code can leak secrets in public npm packages
3 days ago
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
LevelBlue warns of GhostOps risk from rogue AI agents
4 days ago
#
data protection
#
digital transformation
#
cloud security
LevelBlue says unsanctioned AI agents are slipping into enterprise systems, creating a hidden governance and security blind spot for businesses.
AI coding speeds up, but security teams fall behind
4 days ago
#
devops
#
digital transformation
#
application security
AI coding accelerates software delivery, but security teams struggle to keep up as more code, alerts and manual checks pile up.
Grafana Labs launches Grafana 13 with observability updates
4 days ago
#
virtualisation
#
devops
#
data analytics
Grafana Labs rolls out Grafana 13 and a Loki overhaul as it pushes open observability, Kubernetes support and simpler dashboarding.
Chainguard & Cursor tackle AI code supply chain risks
4 days ago
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Tenable flags Microsoft GitHub workflow flaw exposing code
4 days ago
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
Vercel breach linked to compromised Context.ai integration
5 days ago
#
mfa
#
cloud security
#
advanced persistent threat protection
Vercel says an attack on a third-party AI tool let hackers hijack a staff Google Workspace account and reach internal systems.
Identity crisis as machine accounts outnumber humans
Last week
#
pam
#
cloud security
#
iot security
Machine accounts and AI agents are now eclipsing human users in many IT estates, prompting warnings that outdated identity controls are no longer enough.
Orca Security flags AI secrets & supply chain gaps
This month
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Avocado warns on code repository supply chain attacks
This month
#
cloud security
#
phishing
#
application security
Avocado urges Australian firms to tighten repository security as the ACSC reissues a high alert on active supply chain attacks and secrets sprawl.
Codenotary launches AgentMon for AI agent oversight
Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
Dubber cuts observability costs by 25% with Grafana Cloud
Last month
#
virtualisation
#
uc
#
devops
Dubber trims observability run costs by 25% after shifting to Grafana Cloud, simplifying metrics, logs and monitoring across its global platform.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
BeyondTrust warns of 467% rise in enterprise AI agents
Last month
#
crm
#
hyperscale
#
pam
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
BeyondTrust expands Pathfinder to secure AI agents
Last month
#
endpoint protection
#
digital transformation
#
pam
BeyondTrust expands Pathfinder to discover, govern and lock down proliferating enterprise AI agents, identities, privileges and secrets.
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Oasis raises USD $120 million for AI access control
Last month
#
saas
#
digital transformation
#
pam
Oasis raises USD $120 million to expand its AI-first access control platform for non-human identities across large enterprises.
Entro launches AI agent governance tool for enterprises
Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Keeper unveils KeeperDB to tighten database access
Last month
#
data protection
#
hybrid cloud
#
pam
Keeper launches KeeperDB to centralise zero-trust database access, hiding credentials and recording sessions within its existing security vault.