OAuth stories
Security teams face new exposure as AI agents inherit permissions and move data across business systems, Reco says.
Ransomware attacks spread through vendor systems and AI-aided tactics, leaving 7,551 publicly disclosed victims in the latest 12-month period.
Businesses can now let AI agents update Salesforce records and run tasks through Airbyte's new OpenAI Marketplace listing.
Personal accounts used by researchers and officials are being hit by Russian-linked groups, exposing institutions to stealthy account theft and malware.
Startups risk leaked keys, quota throttling and surprise bills unless they tighten controls as AI prototypes move into production.
Employees can now query governed business metrics and documents in one chat, while Looker permissions still apply in Gemini Enterprise.
Security teams must now track AI agents and machine accounts as well as staff, as BeyondTrust expands Pathfinder to cover privileged access.
Enterprise security teams face fresh oversight burdens as Reco joins OpenAI's partner network to monitor agent access and permissions.
Email fraud is now the top incident type, accounting for 45% of cases as attackers bypass multi-factor authentication with stolen credentials.
Corporate travellers at hotels and conference centres were quietly sent to fake Microsoft 365 pages after attackers took over guest Wi-Fi gateways.
Security teams face higher breach costs as ThreatDown expands visibility over unsanctioned AI tools and machine accounts in one console.
Enterprise teams can now switch on controls for AI agents and APIs faster, with Salt Security bundling 100 pre-built policies into its Policy Hub.
Account takeovers are becoming harder to stop as attackers use real-time code theft and fake login pages to bypass Microsoft 365 MFA.
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
Free workshop sandboxes should make it easier for developers to try AWS training without a personal account, credit card or cleanup.
Enterprises can now buy and register third-party AI agents through Google Cloud Marketplace for use inside Gemini Enterprise.
Enterprise AI deployments may be exposing sensitive data through overlooked connector permissions, according to a new governance framework from Vivek Kumar.
Enterprise security teams are being pushed to track what AI agents can access and do across apps, identities and workflows before data is exposed.
Shared code channels could keep AI-assisted development visible to whole teams, with human sign-off still needed before production releases.
Identity-led attacks are speeding up intrusions, with LevelBlue finding business email compromise accounted for 45 per cent of incidents in Q2 2026.