IT Brief UK - Technology news for CIOs & IT decision-makers

Secrets Management stories

Crystal

Identity crisis as machine accounts outnumber humans

4 days ago
#
pam
#
cloud security
#
iot security
Machine accounts and AI agents are now eclipsing human users in many IT estates, prompting warnings that outdated identity controls are no longer enough.
Flux result 6e43f861 242a 4606 a620 43480305c4e9

Orca Security flags AI secrets & supply chain gaps

Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Flux result 2dd6e765 d72a 468e ae19 7b5d4c3c4c21

Codenotary launches AgentMon for AI agent oversight

Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
Flux result 86c5d3ff 8544 4b88 ac41 93781b8158bc

AppOmni adds Heisenberg mode after LiteLLM supply attack

Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Fletcher davis

BeyondTrust warns of 467% rise in enterprise AI agents

Last month
#
crm
#
hyperscale
#
pam
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
Beyondtrust

BeyondTrust expands Pathfinder to secure AI agents

Last month
#
endpoint protection
#
digital transformation
#
pam
BeyondTrust expands Pathfinder to discover, govern and lock down proliferating enterprise AI agents, identities, privileges and secrets.
Editorial compromised software supply chain key token leak dark

Trivy GitHub breach exposes CI/CD supply chain risk

Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Secure enterprise data center digital agents access gates ops room

Oasis raises USD $120 million for AI access control

Last month
#
saas
#
digital transformation
#
pam
Oasis raises USD $120 million to expand its AI-first access control platform for non-human identities across large enterprises.
Corporate security ops room network map ai agents permissions governance

Entro launches AI agent governance tool for enterprises

Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Secure ai dev pipeline centralized governance monitoring icons

Backslash adds cross-tool governance for AI coding Skills

Last month
#
cloud security
#
application security
#
advanced persistent threat protection
Backslash adds cross-tool governance to discover, vet and monitor 'Skills' powering AI coding assistants like Cursor, Claude Code and Copilot.
Us it security ops room zero trust glass server rack workstation

Keeper unveils KeeperDB to tighten database access

Last month
#
data protection
#
hybrid cloud
#
pam
Keeper launches KeeperDB to centralise zero-trust database access, hiding credentials and recording sessions within its existing security vault.
Laptop code leaking secrets glowing keyholes cloud data exposure

AI surge drives record secrets sprawl across GitHub

Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
Cinematic secure ops center unified access ai devices glowing vault

1Password debuts Unified Access to secure AI agents

Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
Story 301609

Okta unveils blueprint to lock down AI agents at work

Last month
#
robots
#
data protection
#
siem
Okta sets out blueprint and tools to corral workplace AI agents, promising tighter discovery, access control and rapid kill switches.
Glowing locked cloud icon with multicolor public private hybrid

Entrust launches cloud cryptographic security platform

Last month
#
private cloud
#
hybrid cloud
#
digital transformation
Entrust unveils cloud-based cryptographic security platform to centralise key, certificate and secrets management across hybrid IT estates.
Atlassian williams

Keeper & Williams F1 launch identity-first security push

Last month
#
data protection
#
digital transformation
#
pam
Keeper Security has kicked off a global identity-first cybersecurity campaign as it enters a third season backing the Atlassian Williams F1 team.
Hybrid cloud network stolen digital identity glowing key figure

Google report warns identity is weak link in cloud

Last month
#
malware
#
ransomware
#
hybrid cloud
Attackers are ditching malware for stolen identities, misconfigurations and abused AI tools, Google warns in its latest cloud threat report.
Moody engineer cicd pipelines morphing into shadowy hands vaults

JFrog flags 13 critical CI/CD flaws in GitHub workflows

Last month
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Asian engineer cybersecurity breach red warnings cloud repos

Claude Code flaws expose new risks in AI dev tools

Last month
#
devops
#
cloud security
#
application security
Claude Code flaws found by Check Point could let malicious repos run code and grab API keys before developers confirm a project is trusted.
It sec ops room analysts lock network and jira style board view

Keeper connects Jira workflows with privileged access

Last month
#
siem
#
digital transformation
#
pam
Keeper launches native Jira integrations to tie security incident workflows directly to privileged access approvals while retaining zero-knowledge controls.