Visualização normal

Antes de ontemCyber Security News

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

9 de Setembro de 2026, 09:51

Austin, Texas / USA, September 9th, 2026, CyberNewswire

Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them.

SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems have become the most common route attackers take into the enterprise.

SpyCloud 2026 Identity Threat Report, Source: SpyCloud

The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer.

NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them.

While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report.

Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.

Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day.

These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.

“That asymmetry is what attackers are exploiting,” said Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer. “Every one of these identities is a standing invitation that renews itself until someone notices.”

This year’s report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees across North America (US and Canada), the United Kingdom, and select European markets Spain, Germany, the Netherlands, Austria, and Switzerland.

It benchmarks how organizations detect, remediate, and govern identity threats across human and non-human identities.

Additional key findings include:

  • AI adoption has outpaced governance. Nearly all organizations (91%) use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for the resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access privileged connections operating outside normal governance and monitoring.
  • Exposed session blind spots track with higher event rates. Organizations that had visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate (37%) than those that could not (50%). 
  • Session cookies and tokens let attackers bypass authentication controls like MFA by resuming an already-authenticated session. This gives them trusted access to applications and data, it’s no surprise then that SpyCloud research shows that session data has overtaken passwords as attackers’ top target.
  • Phishing and malware remain the delivery mechanism. Phishing and social engineering is cited as a common access path for identity events (37%) with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices only.
  • Malware and exposed access top the list of supply chain identity events. Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the leading reported causes of supply chain identity events.
  • Third-party exposures are getting found, but not closed. Nearly 40% of organizations have no consistent process to confirm that a third-party identity exposure was actually resolved, even as 32% name enhancing supply chain and vendor risk management among their planned investments for the next 12 to 18 months.

Non-human identities and third-party exposures are creating new paths into the enterprise, while stolen sessions give attackers ways around controls designed to protect authenticated users.

“Every control that works pushes attackers toward what it doesn’t cover we hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections,” added Hilligoss.

“SpyCloud continues to track threat actor behavior closely to understand where attackers are moving, what data they value, and how those patterns evolve over time.”

Continuous monitoring & automation separate the most resilient identity programs

Identity exposure creates an ongoing operational burden that extends well beyond the initial incident, and how quickly organizations respond has a direct impact on business outcomes.

Those relying on manual, case-by-case remediation reported higher incident response costs than organizations with high levels of automation (39% versus 32%) and greater loss of customer or partner trust (47% versus 36%).

The report also introduces SpyCloud’s Identity Threat Protection Maturity Model, which groups respondents into four maturity tiers Reactive, Building, Operational, and Optimized across identity exposure visibility, monitoring, governance, automation, and remediation.

The findings reflect that the more mature an identity program gets, the more it relies on continuous identity exposure monitoring and automated remediation – and that combination is what actually drives incident rates down.

At enterprise scale, some share of an organization’s employees, vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are. What changes business outcomes is how long that exposure stays usable.

“Most identity programs are still measured on whether an exposure happened. That’s the wrong scoreboard,” said Damon Fleury, Chief Product Officer at SpyCloud.

“Organizations that pair continuous identity monitoring with automated remediation of workforce exposures create the greatest friction for criminals and gain the biggest edge in preventing follow-on attacks.”

Users can access the full, no form-fill 2026 SpyCloud Identity Threat Report and benchmark their organization against the Identity Threat Protection Maturity Model by taking the free assessment here.

About SpyCloud

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud.

Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings.

Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide.

Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.

To learn more and see insights on your company’s exposed data, visit spycloud.com.

Contact

Account Director

Emily Brown

REQ on behalf of SpyCloud

spycloud@req.co

The post SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise appeared first on Cyber Security News.

  • ✇Cyber Security News
  • AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale Cybernewswire
    Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling and maintaining a stack of disconnected components. AgentZ consolidates those pieces. The p
     

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

27 de Agosto de 2026, 06:34

Menlo Park, California, USA, August 27th, 2026, CyberNewswire

AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows.

AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling and maintaining a stack of disconnected components.

AgentZ consolidates those pieces. The platform is built on a straightforward model of Organizations, Workspaces, Agents, Workflows, and Sandboxes, with users and roles sitting across that structure to provide centralized administration and access control.

A workflow can use an agent for computation, a sandbox for isolation, skills for reusable capabilities, credentials injected at runtime, and triggers that determine when the workflow runs.

Key Capabilities

  • No model lock-in. AgentZ is model-agnostic, with support for OpenAI, Claude, Grok, and other models. Teams can change the underlying LLM without rebuilding the surrounding agent infrastructure, because agents, workflows, skills, and runtime controls are kept separate from the model.
  • Isolated execution environments. Every agent runs inside its own sandbox with a dedicated computer and filesystem. Teams configure vCPU and RAM, filesystem read and write access, domain whitelisting, package management, environment variables, and network access, creating a defined boundary around where an agent can execute and what it can touch.

Availability

  • Visibility into what actually happened. An agent’s final response does not show the full execution path. AgentZ provides visual workflow graphs, execution traces, audit logs, workflow steps, agent activity, and tool interactions, so teams can debug and review a run rather than infer it from the output.
  • Structure for multiple teams. Organizations provide centralized administration while workspaces isolate teams and use cases. Users inherit access through roles, shared resources are managed centrally, and enterprise deployments can delegate computation at the workspace level.
  • Deployment on the organization’s terms. AgentZ supports SaaS, on-prem, and air-gapped deployment, alongside bring-your-own-LLM, giving teams control over both where the platform runs and which models power their agents.

Agentic AI platform with security built in

AccuKnox is positioning AgentZ as an AI platform with security built in rather than a security product that happens to use AI.

Security is central to the design, through zero-trust controls, tool-level permissions, and sandboxed execution, but it is not the boundary of the product.

The same platform supports a security investigation workflow, a sales intelligence workflow, a competitive intelligence workflow, an engineering automation workflow, an HR process, or recurring finance and operations tasks.

The launch roadmap spans security, sales, marketing, engineering, HR, finance, healthcare, education, and operations.

The core difference is defined around four areas: model-agnostic, deploy anywhere, secure by default, and built for organizations.

An agent that can call tools is not the hard part. The hard part is deciding what it is allowed to touch, containing the blast radius when it gets something wrong, and being able to reconstruct the run afterwards. AgentZ puts sandboxing, tool-level permissions, and runtime credential injection underneath the workflow itself, so every team is not rebuilding those controls from scratch,” – said Rahul Jadhav, co-founder and CTO, AccuKnox.

Most organizations are past the demo phase and are now asking a harder question, which is whether they can let agents do real work inside the business. That takes structure, not another framework,” said Nat Natraj, co-founder and CEO, AccuKnox. “AgentZ gives teams a place to build agents, run them under controls a security team will actually accept, and manage them across the organization, using their own models and their own infrastructure.” – said Nat Natraj, co-founder and CEO, AccuKnox. 

About AccuKnox 

AccuKnox delivers a Zero Trust Security platform for AI, API, Application, Cloud, and Supply Chain Security.

Incubated out of R&D innovator, SRI International (Stanford Research Institute), AccuKnox holds seminal Zero Trust security patents and is backed by top-tier investors including National Grid Partners, Dolby Family Ventures, Avanta Ventures, and the 5G Open Innovation Lab. https://accuknox.com

Contact

Syed Hadi

Product Marketing & Partnerships

AccuKnox

syed.hadi@accuknox.com

The post AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale appeared first on Cyber Security News.

VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI

14 de Agosto de 2026, 13:31

Selidan, USA, August 14th, 2026, CyberNewswire

New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influencing how the vehicle history platform appears across Google and AI systems

VINclarity has published a new investigation into what researchers describe as a coordinated online reputation attack targeting the vehicle history platform across Reddit, YouTube, Google Search and AI-powered discovery systems.

The investigation, “VINclarity Becomes the Next Target: Inside the Coordinated Reputation Attack Playbook”, examines a cluster of negative content built around subscription-charge allegations and searches such as “VINclarity scam,” “VINclarity fraud,” “VINclarity reviews” and “is VINclarity legit.”

According to the report, the pattern closely resembles an earlier eFAQ investigation into reputation attacks targeting Google Search and LLM systems, which was later covered by Yahoo Finance.

Suspicious Activity Behind an Archived Reddit Thread

One of the most visible pieces of content examined was an archived Reddit thread in r/Scams accusing VINclarity of misleading customers.

Researchers identified nine participating accounts whose activity was limited to one or two comments focused exclusively on the company. Another account had already been suspended, while a separate long-dormant account returned specifically to participate in the discussion.

The thread itself contained information that complicated its headline.

According to the investigation, the original poster confirmed receiving a full refund after contacting VINclarity support through a single email. Other established Reddit users also challenged claims that the recurring membership fee had been hidden.

The report argues that this creates a significant gap between the negative framing visible in a Google result and the fuller context available inside the underlying discussion.

Checkout Evidence Challenges Hidden Subscription Claims

Unexpected subscription charges were the central allegation repeated across Reddit, YouTube and BBB content reviewed in the investigation.

Researchers compared those claims directly with VINclarity’s checkout process and documented the subscription disclosure at three separate stages.

The first pricing screen presents users with two distinct options: a $10 one-time vehicle report and a membership plan.

The second screen states that the membership begins with a $1 seven-day trial and renews at $24.99 per month. The same section explains that customers can cancel through their account dashboard or contact support.

The final payment screen repeats the terms again. Before the transaction can be submitted, the customer must actively select a consent checkbox confirming the trial period, the $24.99 monthly renewal and the cancellation conditions.

The order summary simultaneously displays “7-day Trial Membership” and “Total today: US $1.00.”

Payment cannot be completed without this confirmation.

VINclarity also maintains a public FAQ addressing billing and subscription charges.

The investigation argues that the three-stage disclosure conflicts with content portraying the recurring membership as concealed from customers.

YouTube Content Followed a Similar Pattern

The investigation also identified four YouTube videos appearing across separate channels within a similar timeframe.

According to the report, none of the creators documented first-hand use of VINclarity before publishing their conclusions.

One video explicitly encouraged engagement intended to increase its visibility for brand-related searches.

Three others followed similar production structures involving synthetic voiceovers, recordings of VINclarity’s interface and negative conclusions based primarily on aggregated complaints. One also contained affiliate links to competing services.

Researchers described the similarities in timing, format, search targeting and conclusions as consistent with coordinated production.

BBB Scam Tracker Added a Third Search Surface

Two additional entries were identified through BBB Scam Tracker.

The report says the significance lies in how separate high-authority platforms can reinforce one another.

A consumer researching the company may encounter a negative Reddit result, a YouTube video questioning its legitimacy and a BBB Scam Tracker entry referring to fraud.

Because each result appears on a different trusted domain, the collection can resemble independent confirmation even when the underlying allegations have not been independently verified.

The effect is cumulative. Several separate search results can make one narrative appear broadly corroborated while occupying multiple positions across the same search environment.

How the Alleged Reputation Attack Mechanism Works

The investigation argues that repetition across platforms is the central mechanism behind this type of campaign.

A single piece of negative content does not need to dominate Google. Instead, different content can be distributed across Reddit, YouTube, complaint platforms and other domains with strong search visibility.

Each source reinforces similar associations involving scams, fraud, complaints, billing disputes and negative customer experiences.

Once indexed, those pages can occupy multiple parts of a search results page at the same time.

The same material can then become input for AI-powered discovery systems.

Google AI Overviews, Gemini, ChatGPT, Perplexity and other AI products can use publicly available indexed web content when generating responses about companies.

The investigation documented Google AI-generated content reflecting concerns surrounding VINclarity subscription charges.

Researchers argue that automated systems may absorb repeated negative framing while giving less prominence to contextual details such as suspicious account histories, refunds received by complainants or subscription terms shown during checkout.

This may create a feedback loop: negative content gains search visibility, repeated visibility makes the narrative appear more established, and AI-generated summaries can reproduce similar framing for future users.

The report identifies this cycle as the core of the reputation attack playbook.

Findings Mirror Earlier eFAQ Investigation

The findings closely resemble the reputation attack pattern previously documented by eFAQ.

That investigation described disposable Reddit accounts, coordinated negative content, YouTube activity and recurring allegations involving subscription charges. The findings later received broader media coverage, including reporting by Yahoo Finance.

According to the VINclarity investigation, researchers examining the earlier case subsequently identified similar account patterns targeting unrelated businesses.

VINclarity is described as the second documented case showing the same broader playbook.

The investigation does not identify who commissioned or organized the campaign. Its conclusions focus on observable signals including account histories, publishing patterns, repeated allegations, similar content structures and coordinated positioning across search.

VINclarity says evidence gathered during the investigation is being submitted through Google Search Quality spam reports, Reddit moderation channels and YouTube reporting systems.

As search engines and AI assistants play a larger role in how consumers evaluate companies, the report argues that distinguishing genuine customer feedback from coordinated reputation content is becoming increasingly important.

The full VINclarity investigation contains the documented Reddit activity, YouTube content, BBB entries, checkout evidence and search amplification patterns examined in the case.

About VINclarity

VINclarity provides NMVTIS-connected vehicle history reports for consumers researching used vehicles. Reports can include accident history, title status, open recalls, odometer records and ownership history.

More information is available at VINclarity.com.

Contact

Vadym Zharkov

Datax Group

legal@datax.group

The post VINclarity Publishes Investigation Into Alleged Scam and Fraud Reputation Attack Across Search and AI appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again Kavichselvan
    Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endrazine, announced the rebirth of the original Bugtraq mailing list. Established in 1993, Bugtraq is the original mailing list where cybersecurity vulnerabilities, mitigations, and cutting-edge techniques have been discussed at scale. With over 120,000 references from the NVD/CVE database, Bugtraq and its associated website securityfoc
     

Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again

8 de Agosto de 2026, 06:09

Sophia Antipolis, France, August 7th, 2026, CyberNewswire

At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endrazine, announced the rebirth of the original Bugtraq mailing list.

Established in 1993, Bugtraq is the original mailing list where cybersecurity vulnerabilities, mitigations, and cutting-edge techniques have been discussed at scale.

With over 120,000 references from the NVD/CVE database, Bugtraq and its associated website securityfocus.com are a pillar of modern information security, providing moderated, quality information to Product Security teams and the larger infosec community, free of charge.

For roughly a third of all catalogued vulnerabilities, SecurityFocus remains a primary technical reference.

In a time where cybersecurity information fades into oblivion, between ephemeral social media posts, paywalls, gated information, or dead links, providing a place where security researchers may share their work and have it archived for posterity is of prime importance to the cybersecurity community.

Bugtraq is a community service and an open platform available to all security researchers. There is no paywall, no gated access, no commercial agenda. The list exists to serve the cybersecurity community.

“At the end of the day, Bugtraq is what its users make of it,” said Jonathan Brossard, adding: “We are providing the platform. The community decides what it becomes.”

To this end, SecurityFocus features two lists:

DEF CON founder Jeff Moss welcomed the relaunch in a public post to the list: “I believe the bug belongs to the finder and hopefully this can become a neutral place to discuss them.”

Subscriptions and archives are available at https://securityfocus.com and https://bugtraq.ai.

We would like to express our gratitude to past moderators — legendary and anonymous alike for their community service, running a mailing list that is a tremendous source of information, on a daily basis. You shaped the field of information security.

We would finally like to express our gratitude to Solar Designer for preserving the archives of Bugtraq. For this, and countless other accomplishments, you are a legend.

Call for Volunteers: Seeking Moderators to Help Steer the Community

Should you have experience in moderating full disclosure mailing lists, time to contribute, and a desire to help the community, interested parties feel free to reach out.

About Bugtraq

Founded in 1993, Bugtraq is one of the longest-running cybersecurity mailing lists. For over two decades it served as the primary channel for vulnerability disclosure, security advisories, and original research. The list is now independently operated and hosted at securityfocus.com.

Contact

Security Researcher

Jonathan BROSSARD

MOABI Solutions

endrazine@psirt.com

The post Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again appeared first on Cyber Security News.

❌
❌