惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
Intezer
The Register - Security
The Register - Security
博客园 - 三生石上(FineUI控件)
博客园_首页
量子位
Hugging Face - Blog
Hugging Face - Blog
Engineering at Meta
Engineering at Meta
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
N
Netflix TechBlog - Medium
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
GbyAI
GbyAI
D
Docker
M
MIT News - Artificial intelligence
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
T
Tailwind CSS Blog
S
SegmentFault 最新的问题
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
有赞技术团队
有赞技术团队
IT之家
IT之家
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Troy Hunt's Blog
Cyberwarzone
Cyberwarzone
Recorded Future
Recorded Future
H
Help Net Security
L
LINUX DO - 热门话题
罗磊的独立博客
Google DeepMind News
Google DeepMind News
NISL@THU
NISL@THU
SecWiki News
SecWiki News
T
Threat Research - Cisco Blogs
T
Threatpost
Cloudbric
Cloudbric
G
GRAHAM CLULEY
S
Security @ Cisco Blogs
Hacker News - Newest:
Hacker News - Newest: "LLM"
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
P
Proofpoint News Feed
V2EX - 技术
V2EX - 技术
L
LangChain Blog
The Cloudflare Blog
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
B
Blog
T
The Blog of Author Tim Ferriss

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password Expanding Programmatic Access to 1Password | 1Password Zero knowledge vs. a malicious server: A look at ETH Zurich’s research | 1Password Agents are making filesystems cool again | 1Password Black History Month employee spotlight: Joseph Ojelade | 1Password 1Password's new benchmark teaches AI agents how not to get scammed | 1Password Streamlining SaaS onboarding and offboarding | 1Password 3 common SaaS Management challenges and how to avoid them | 1Password How 1Password Is Evolving Its Partner Ecosystem | 1Password How to build secure agent swarms that power production-grade autonomous systems | 1Password From magic to malware: How OpenClaw's agent skills become an attack surface | 1Password Solving the unsanctioned SaaS problem | 1Password 1Password and 60 Day Hustle: cybersecurity for small businesses | 1Password Security advisory for AI-assisted browsing interactions with the 1Password browser extension | 1Password It’s incredible. It’s terrifying. It’s OpenClaw. | 1Password Managing the risks of social logins | 1Password What’s the first security tool your small business should buy? | 1Password As AI Supercharges Phishing Scams, 1Password Introduces Built-In Protection | 1Password How to interview with confidence at 1Password | 1Password Five tips for successful SaaS Management | 1Password SaaS Manager | 1Password Why SaaS License Waste Is a Cost and Security Problem | 1Password AI is changing the IDE. With 1Password, security keeps up | 1Password How IT teams can get a handle on shadow IT | 1Password Bringing secure, just-in-time secrets to Cursor with 1Password | 1Password The Chasing Entropy Podcast Season One is in the Books | 1Password Now available via QBS Software: 1Password Enterprise Password Manager – MSP Edition | 1Password The role of credentials in the AI espionage campaign reported by Anthropic | 1Password The hidden offboarding step draining your budget | 1Password AWS and 1Password: Innovation in AI and beyond | 1Password Simplifying credential security on OpenAI Atlas | 1Password From Social Work to Social Impact: Growing at 1Password | 1Password Improving in-page notifications in the 1Password browser extension | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password Now available via Renaissance: 1Password Enterprise Password Manager – MSP Edition | 1Password Behind the wheel at Oracle Red Bull Racing | 1Password Securing MCP servers with 1Password: Stop credential exposure in your agent configurations | 1Password What’s new in 1Password Enterprise Password Manager - Q4, 2025 | 1Password Belonging as a catalyst for high performance | 1Password Password habits are worsening, but leaders see a path to passwordless | 1Password A simpler, faster way to unlock 1Password | 1Password Oracle Red Bull Racing Episode 4, CIO Matt Cadieux | 1Password 70% of IT and security pros say SSO is falling short | 1Password 1Password's Phishing Survey: Avoid Holiday Phishing Scams | 1Password Securing the Win | 1Password SaaS optimization: How to maximize value and reduce costs | 1Password The enterprise AI crisis: Unsanctioned tools and unenforced policies | 1Password An Identity Security taxonomy for Agentic AI | 1Password Introducing new .env file support in 1Password environments | 1Password Speed and security: Mark Hazelton on protecting Oracle Red Bull Racing’s most valuable asset – its data | 1Password 1Password for Good: Giving back during cybersecurity awareness month | 1Password Utah Mammoth and Utah Jazz score with identity security | 1Password Oracle Red Bull Racing CEO and Team Principal | 1Password Three signs you need a SaaS Management Platform | 1Password Closing the credential risk gap for AI agents using a browser | 1Password Microsoft and Dropbox password managers are sunsetting: What it means and what to do next | 1Password From hackathon nerves to internship wins: Kavya’s journey at 1Password | 1Password 1Password now available in Comet, the AI-powered browser by Perplexity | 1Password 1Password announces new integration with Zscaler | 1Password Breaking the mold: Why more women should consider a career in sales | 1Password What security leaders need to know about mergers and acquisitions | 1Password Clickjacking: What it means for 1Password users | 1Password Blog | 1Password Do any CISOs feel lucky? | 1Password How to lead with confidence in the AI era: a conversation with Nancy Wang, VP, Engineering | 1Password New Device Trust Check makes browser extension enforcement easier | 1Password Purpose, performance, and trust: Inside the culture powering 1Password’s next chapter | 1Password Now available on Pax8 Marketplace: 1Password Enterprise Password Manager - MSP Edition | 1Password The security principles guiding 1Password’s approach to AI | 1Password Choosing the right SaaS management platform for your business | 1Password Simplify access reviews with 1Password SaaS Manager | 1Password How great usability tripled Duke University's password manager adoption | 1Password
AI and security at Black Hat: 5 key takeaways from a security expert panel | 1Password
info@1password.com (1Password) · 2025-08-26 · via Blog on 1Password Blog

In late July, we published new research on the risks of unmanaged AI, revealing four major security challenges companies face when AI slips under the radar.

Those findings set the stage for a lively expert panel at Black Hat, where security leaders explored “Weaponized Autonomy: The rise of AI agents as enterprise threat vectors.” The panel included:

  • Joe Carson, chief security evangelist and advisory CISO, Segura

  • Anand Srinivas, vice president of AI, 1Password

  • Wendy Nather, senior research director, 1Password

  • Dave Lewis, global advisory CISO

The conversation confirmed much of what our research uncovered: employees are adopting AI at a breakneck pace, governance is lagging, and opportunity and risk are growing in equal measure.

As organizations race to embrace AI, the panelists dug into the key considerations security leaders should keep in mind as they integrate AI agents and solutions:

1. Zero trust principles need an AI upgrade

Panelists agreed: zero trust isn’t going anywhere. Its core principles of validating every access request, minimizing privilege, and verifying continuously are still the right foundation.

The challenge? Wendy Nather noted that zero trust itself will need to evolve. “Now, most of the factors that we're used to using for zero trust are bound to a human being, biometrics, and physical presence. With AI, we’re going to have to rethink a lot of that,” she said.

AI introduces non-human identities into the equation. Enterprises will need to extend their access controls to AI agents and tools, applying least privilege, just-in-time access, and revocability. Think of it as zero trust, but now applied to our new AI agent "digital colleagues".

2. Criminals are getting creative fast

Until recently, AI hadn’t made a major appearance in the cybercriminal toolkit. That’s changing quickly, as attackers have started to take advantage of generative AI and AI agents. The panel shared examples of attackers using AI to:

  • Accelerate the analysis of stolen data to fine-tune ransom demands.

  • Replace human cybercriminals with AI bots to make it easier than ever to do mass outreach over messaging services, emails, and so forth.

Joe Carson also started to see cybercriminals attack new regions with AI, increasing their language capabilities. He shared, “The Estonian language, like Finnish, is very complex, so we very seldom get a lot of phishing attacks. But at the end of 2023, it accelerated significantly. We started seeing with artificial intelligence that language is no longer a barrier.”

As AI continues to lower barriers to entry for attackers, operations are accelerating, and scams are becoming sharper, more convincing, and harder to spot.

3. Shadow AI and governance gaps are a recipe for trouble

One theme was loud and clear: many CISOs don’t have visibility into how their organizations are using AI.

The panel pointed to research showing that more than half of security leaders (56%) estimate that between 26% and 50% of their AI tools and agents are unmanaged. Dave Lewis noted that while CISOs have governance frameworks for older IT implementations, most haven’t adapted them for AI. As one CISO at a CISO roundtable in Vienna put it, “We closed the door to AI products, but they’re now coming through the window.”

Their advice to get ahead of the AI governance challenge? Start with inventory and visibility, then implement clear governance rules that allow security to act quickly when unauthorized AI use appears.

4. Business demand is outpacing security preparedness

For many companies, AI has gone from “maybe” to “must-have” in record time. But panelists cautioned that hype is driving adoption faster than security can keep up.

Although securing AI shares similarities with past emerging technologies, the people building it are changing. Wendy Nather observed, “With web applications and then mobile, new groups came in who hadn’t learned the security lessons we had. With AI, we’re going to see a whole new crowd that doesn’t understand the practices we’ve improved, and they’ll make those same mistakes all over again.”

The result is a widening gap between business ambition and safe deployment. They recommended tabletop exercises to define how AI should be handled, including scenarios where security might need to cut off shadow AI, even if it’s the CEO using it.

5. Using AI can be a superpower and a liability

The closing sentiment was balanced: AI is a transformative tool for automation, speed, and efficiency, but it’s also a way to “shoot yourself in the foot.” Without strict controls, over-permissioned AI agents and poorly scoped applications can expose sensitive data and create new attack surfaces.

Anand Srinivas stressed that security must be paired with usability. “It also has to be easy to use, because if it’s not, people will find a way to circumvent it,” he said.

Looking forward, panelists see promise in agent-to-agent security standards, federated identity models, and extending digital wallet concepts to AI. Each of these will provide enterprises with better ways to manage identity, authentication, and access for AI and humans alike.

Final word

The takeaway from this panel wasn’t “fear AI,” it was “govern AI.” With 54% of security leaders admitting their governance enforcement is weak, the industry is running without the guardrails it needs for safe, successful AI adoption. The good news? It’s not too late. If organizations put the proper safeguards in place, AI becomes a force multiplier for security programs—accelerating detection, response, and resilience. Ignore them, and it could become the next big vulnerability we all scramble to contain.