Secrets Management stories
Identity crisis as machine accounts outnumber humans
4 days ago
#
pam
#
cloud security
#
iot security
Machine accounts and AI agents are now eclipsing human users in many IT estates, prompting warnings that outdated identity controls are no longer enough.
Orca Security flags AI secrets & supply chain gaps
Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Codenotary launches AgentMon for AI agent oversight
Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
BeyondTrust warns of 467% rise in enterprise AI agents
Last month
#
crm
#
hyperscale
#
pam
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
BeyondTrust expands Pathfinder to secure AI agents
Last month
#
endpoint protection
#
digital transformation
#
pam
BeyondTrust expands Pathfinder to discover, govern and lock down proliferating enterprise AI agents, identities, privileges and secrets.
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Oasis raises USD $120 million for AI access control
Last month
#
saas
#
digital transformation
#
pam
Oasis raises USD $120 million to expand its AI-first access control platform for non-human identities across large enterprises.
Entro launches AI agent governance tool for enterprises
Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Backslash adds cross-tool governance for AI coding Skills
Last month
#
cloud security
#
application security
#
advanced persistent threat protection
Backslash adds cross-tool governance to discover, vet and monitor 'Skills' powering AI coding assistants like Cursor, Claude Code and Copilot.
Keeper unveils KeeperDB to tighten database access
Last month
#
data protection
#
hybrid cloud
#
pam
Keeper launches KeeperDB to centralise zero-trust database access, hiding credentials and recording sessions within its existing security vault.
AI surge drives record secrets sprawl across GitHub
Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
1Password debuts Unified Access to secure AI agents
Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
Okta unveils blueprint to lock down AI agents at work
Last month
#
robots
#
data protection
#
siem
Okta sets out blueprint and tools to corral workplace AI agents, promising tighter discovery, access control and rapid kill switches.
Entrust launches cloud cryptographic security platform
Last month
#
private cloud
#
hybrid cloud
#
digital transformation
Entrust unveils cloud-based cryptographic security platform to centralise key, certificate and secrets management across hybrid IT estates.
Keeper & Williams F1 launch identity-first security push
Last month
#
data protection
#
digital transformation
#
pam
Keeper Security has kicked off a global identity-first cybersecurity campaign as it enters a third season backing the Atlassian Williams F1 team.
Google report warns identity is weak link in cloud
Last month
#
malware
#
ransomware
#
hybrid cloud
Attackers are ditching malware for stolen identities, misconfigurations and abused AI tools, Google warns in its latest cloud threat report.
JFrog flags 13 critical CI/CD flaws in GitHub workflows
Last month
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Claude Code flaws expose new risks in AI dev tools
Last month
#
devops
#
cloud security
#
application security
Claude Code flaws found by Check Point could let malicious repos run code and grab API keys before developers confirm a project is trusted.
Keeper connects Jira workflows with privileged access
Last month
#
siem
#
digital transformation
#
pam
Keeper launches native Jira integrations to tie security incident workflows directly to privileged access approvals while retaining zero-knowledge controls.