Secrets Management stories
Identity crisis as machine accounts outnumber humans
4 days ago
#
pam
#
cloud security
#
iot security
Machine accounts and AI agents are now eclipsing human users in many IT estates, prompting warnings that outdated identity controls are no longer enough.
Keeper adds browser isolation to privileged access
Last week
#
firewalls
#
data protection
#
network security
Keeper Security has upgraded KeeperPAM with remote browser isolation, multi-tab support and AI session monitoring to better secure web-based privileged access.
Orca Security flags AI secrets & supply chain gaps
Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Codenotary launches AgentMon for AI agent oversight
Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
BeyondTrust warns of 467% rise in enterprise AI agents
Last month
#
crm
#
hyperscale
#
pam
BeyondTrust warns a surge of unsupervised AI agents is creating a hidden “shadow workforce” with admin-level access inside enterprises.
BeyondTrust expands Pathfinder to secure AI agents
Last month
#
endpoint protection
#
digital transformation
#
pam
BeyondTrust expands Pathfinder to discover, govern and lock down proliferating enterprise AI agents, identities, privileges and secrets.
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Oasis raises USD $120 million for AI access control
Last month
#
saas
#
digital transformation
#
pam
Oasis raises USD $120 million to expand its AI-first access control platform for non-human identities across large enterprises.
Entro launches AI agent governance tool for enterprises
Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Keeper unveils KeeperDB to tighten database access
Last month
#
data protection
#
hybrid cloud
#
pam
Keeper launches KeeperDB to centralise zero-trust database access, hiding credentials and recording sessions within its existing security vault.
AI surge drives record secrets sprawl across GitHub
Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
1Password debuts Unified Access to secure AI agents
Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
ControlPlane unveils enterprise support for OpenBao
Last month
#
encryption
#
pam
#
cloud security
ControlPlane launches enterprise support for OpenBao as IBM's USD $6.4 billion HashiCorp deal drives demand for open source Vault alternatives.
Entrust launches cloud cryptographic security platform
Last month
#
private cloud
#
hybrid cloud
#
digital transformation
Entrust unveils cloud-based cryptographic security platform to centralise key, certificate and secrets management across hybrid IT estates.
Keeper & Williams F1 launch identity-first security push
Last month
#
data protection
#
digital transformation
#
pam
Keeper Security has kicked off a global identity-first cybersecurity campaign as it enters a third season backing the Atlassian Williams F1 team.
Google report warns identity is weak link in cloud
Last month
#
malware
#
ransomware
#
hybrid cloud
Attackers are ditching malware for stolen identities, misconfigurations and abused AI tools, Google warns in its latest cloud threat report.
JFrog flags 13 critical CI/CD flaws in GitHub workflows
Last month
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Claude Code flaws expose new risks in AI dev tools
Last month
#
devops
#
cloud security
#
application security
Claude Code flaws found by Check Point could let malicious repos run code and grab API keys before developers confirm a project is trusted.
Keeper connects Jira workflows with privileged access
Last month
#
siem
#
digital transformation
#
pam
Keeper launches native Jira integrations to tie security incident workflows directly to privileged access approvals while retaining zero-knowledge controls.