惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
Apple Machine Learning Research
Apple Machine Learning Research
量子位
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
博客园 - 聂微东
博客园_首页
D
Docker
博客园 - 叶小钗
S
SegmentFault 最新的问题
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
F
Fortinet All Blogs
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
爱范儿
爱范儿
腾讯CDC
罗磊的独立博客
雷峰网
雷峰网
博客园 - Franky

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Companies are failing to keep up with AI’s identity spraw...
Eric Geller · 2026-06-10 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

Three-quarters of organizations say they aren’t fully overseeing the activities of user accounts belonging to agents and other AI tools.

Published June 10, 2026

A digital blue fingerprint lifted being lifted off a mirrored surface against a black background. Binary code makes up the fingerprint.

Getty Images

Dive Brief:

  • The rate of data breaches at companies that widely use AI tools is significantly higher than the rate at companies that don’t — 43% compared with 11% over the past 12 months — the identity security firm Netwrix said in a report published on Wednesday.
  • AI tools such as agents significantly increase organizations’ “identity footprint,” creating more gaps that hackers can exploit, Netwrix said.
  • At the same time, Netwrix found, the companies using AI the most widely are also the ones taking identity management the most seriously.

Dive Insight:

Netwrix’s report highlights the security risks of the sprawling web of user accounts and other identities that companies must create to use agents, copilots and other AI tools.

“AI agents are now acting on behalf of humans against sensitive data,” Netwrix researchers wrote. “Non-human identities need the same operational rigor long applied to privileged human access.”

And yet many companies aren’t taking identity management seriously, the report found. Roughly three-quarters lack “a single, unified view of sensitive data and which identities have access to it,” researchers said. More than half of organizations lack an up-to-date database of sensitive data, 71% can’t quickly determine which identities can access which data and 70% don’t have a security strategy linking data protection with identity governance.

Identity management is far from a new challenge for enterprises, but AI has magnified it, and companies are not always keeping pace. Three-quarters of organizations aren’t fully overseeing what AI identities are doing in their systems, even as 41% say they’re letting AI agents access sensitive data and perform vital tasks.

Netwrix’s report highlights how hackers have used identity security weaknesses as entry points in target networks. Three-quarters of incidents in which hackers access sensitive data involve compromises of identities or misconfigured account permissions. But despite widespread corporate awareness of this threat, most companies aren’t mitigating it.

Seventy-six percent of organizations can’t immediately revoke inactive accounts’ data access, according to the report, and 72% say their accounts have excessive permissions or they’re unsure which permissions their accounts have. Even more worrisome, roughly two-thirds of organizations said they believe at least some of their accounts have unnecessary access to vital data. Only one-quarter of companies said they were fully confident in their ability to detect potentially dangerous account access permissions.

The report — which also includes data about companies’ readiness to govern their AI systems and the frequency of unauthorized-identity-access incidents in different organization size segments — is based on a worldwide survey of 2,317 security professionals at 1,889 organizations in 60 industries.