惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
小众软件
小众软件
J
Java Code Geeks
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
L
LangChain Blog
博客园 - 司徒正美
量子位
Y
Y Combinator Blog
C
Check Point Blog
T
Tailwind CSS Blog
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
V
V2EX
阮一峰的网络日志
阮一峰的网络日志

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
The rise of machine identities and agentic AI: Securing t...
Help Net Security · 2026-06-16 · via Help Net Security

In the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cybersecurity landscape, driven by the rise of artificial intelligence (AI), particularly agentic AI, which is giving systems unprecedented autonomy within the enterprise.

You can watch our full discussion here:

securing machine identities

The conversation reinforced something I’ve been thinking about for a while: we’re entering a new phase of identity security. It’s no longer just about protecting people’s access; it’s about protecting the data, systems, and trust boundaries that people and machines interact with.

For years, identity security has been centered on humans, ensuring that the right person has the right level of access to the right resources. But now, the same principle applies to non-human entities: machines, APIs, bots, and increasingly, AI agents. These new “digital actors” authenticate, access sensitive information, execute workflows, and even make decisions, often faster and at greater scale than any human ever could.

That shift means our focus as security leaders must evolve from simply asking “Who is the person?” to asking “What entity, human, machine, AI, is accessing my data, and can I trust it?”

From service accounts to autonomous agents: A new kind of identity sprawl

Today, for every human identity, an enterprise may have dozens of machine identities—automatically created, rarely tracked, and often left behind. With cloud-native architectures, microservices, and automation, this sprawl has exploded. Unfortunately, attackers have noticed too. Compromised machine credentials are now among the most common initial access vectors in major breaches.

Agentic AI: Machines that think and act

In just the past year, agentic AI has advanced at an extraordinary pace. Unlike traditional AI that only generates text or insights, agentic AI gives large language models (LLMs) “arms and legs”, enabling them to take real actions on behalf of humans.

These autonomous agents can log into systems, execute workflows, interact with APIs, and even make decisions about data and security operations. Each carries credentials, tokens, or entitlements. In other words, each represents a new non-human identity with real privileges in your environment.

This introduces a new challenge: replicated privilege at machine speed. A single employee using an AI agent could unknowingly multiply their access tenfold, creating a web of high-privilege entities acting semi-independently under their account.

Combined with the existing sprawl of service accounts and cloud integrations, the attack surface expands dramatically—where a single compromised agent or API key can move laterally across environments with devastating speed.

Why visibility is still the hardest problem

Visibility remains the hardest problem. Enterprises now juggle identities across SaaS apps, multiple clouds, and on-prem environments. Even with advanced tools, many can’t confidently answer:

  • How many non-human identities exist in our environment?
  • What privileges do they have, and are those privileges appropriate?
  • Which identities are linked to AI agents or automation frameworks?
  • Which secrets or credentials are embedded in code or stored insecurely?

At Delinea, we refer to this as discovery, and it’s the essential first step. Our platform uncovers machine and agentic identities wherever they reside and maps how they interact. Once visibility is achieved, organizations can move to governance and control.

Governance and the over-privilege problem

Managing machine entitlements is difficult because, unlike humans, machines don’t protest excessive access. Engineers often over-provision credentials to ensure workflows run smoothly, leading to persistent, unnecessary privileges, a key factor in many breaches.

As AI agents gain autonomy, privilege management becomes both more challenging and increasingly critical. Delinea’s philosophy is simple:

You can’t protect what you can’t see, and you can’t secure what you don’t govern.

We focus on enabling organizations to discover, right-size, and protect every identity—human, machine, or AI.

AI’s dual role: Risk amplifier and security accelerator

AI is a double-edged sword. It’s both a new risk vector and a powerful enabler for defense.

Attackers are already using AI to automate reconnaissance, craft realistic phishing campaigns, and exploit leaked credentials more quickly than human teams can respond. On the other hand, defenders can utilize AI to enhance visibility, detect abnormal behavior, and expedite responses.

At Delinea, we view AI’s role in two ways:

  • Securing customers’ AI: Discover and manage AI agents, enforce least privilege, and govern their access.
  • Using AI for security: Embed intelligence to detect abnormal privilege patterns, recommend remediation, and continuously learn from identity behavior.

As AI becomes increasingly autonomous, the distinction between “identity” and “agent” will blur. Securing that boundary will be one of cybersecurity’s defining challenges.

Practical steps for securing machine and agentic identities

Organizations beginning to address this issue should start with these practical actions:

1. Discover everything: Inventory every credential, key, token, and agent. Continuously scan across all environments.
2. Classify and prioritize risk: Identify over-privileged or dormant accounts and pinpoint those with access to sensitive systems.
3. Apply least privilege and just-in-time access: Remove standing credentials, rotate secrets automatically, and vault sensitive machine secrets.
4. Automate governance: Enforce policy through automated workflows and integrate security into CI/CD pipelines.
5. Monitor continuously: Track anomalies, detect privilege drift, and use AI analytics for early warning.

Identity security isn’t a one-time project; it’s a continuous lifecycle of discovery, governance, and control.

Looking ahead: securing autonomy

We’re moving into an era where software not only executes instructions but also makes decisions. Machine identities and AI agents are now active participants in enterprise operations.

This evolution demands a new model of identity security, one that scales beyond human oversight, uses automation to enforce least privilege, and provides continuous insight into how trust is exercised.

The machines are rising, and our responsibility is to ensure they rise securely.