Secrets Management stories
Enterprise administrators can now warn staff before passwords are pasted into fake sites, as phishing remains a major cause of breaches.
Security teams may miss data theft as AI agents use Telegram and WhatsApp to run locally on endpoints with user-level access.
Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default.
Unapproved AI agents are already exposing firms to hidden security gaps, with LevelBlue saying many are running tools without oversight.
Security teams are struggling to review surging AI-generated code, with 62% saying the workload is getting harder to manage.
The release aims to ease log searching and dashboard management as engineering teams wrestle with rising telemetry volumes and system complexity.
New on-device AI in Android 17 may let phones act across apps, but security analysts warn that broader access could trigger unintended actions.
AI coding agents are increasing supply chain risk, prompting new controls to verify third-party dependencies before they reach production.
A critical flaw in a widely used Microsoft code-sample repository could have let attackers steal secrets and run code through GitHub issues.
Customers were urged to rotate secrets after unauthorised access to Vercel systems exposed a limited set of credentials via a third-party AI tool.
Machines now account for most cloud identities, leaving firms exposed to faster attacks, over-privileged access and AI-driven risks.
Leaked AI credentials and unpatched dependencies are leaving production systems exposed across US and European organisations, Orca Security said.
Enterprises deploying agentic AI are getting a new tool to spot data leaks, policy breaches and runaway costs before they spread.
The malicious packages could leave build systems and Kubernetes clusters exposed, prompting checks across CI/CD pipelines and AI frameworks.
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
BeyondTrust expands Pathfinder to discover, govern and lock down proliferating enterprise AI agents, identities, privileges and secrets.
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
The update lets administrators handle complex web tasks more securely, without losing recording, monitoring or control over file transfers.
Australian organisations face fresh risk of cloud and identity compromise as the cyber watchdog reissues its alert on repository attacks.
A single managed platform has eased pressure on Dubber's lean engineering team as it scales observability across more than one million daily calls.