Identity management

The OWASP LLM Top 10 has a few surprises for you

The OWASP LLM Top 10 has a few surprises for you

This podcast episode breaks down the 2026 OWASP LLM Top 10, highlighting a significant rise in concern for 'Excessive Agency' over traditional prompt injection. It explores the discrepancies between practitioner fears and incident data, particularly regarding misinformation, and advocates for viewing security frameworks as tools for operationalization and cyber resilience, not just compliance. The discussion also covers CISA's new SBOM guidance, emphasizing the need to operationalize supply chain data for effective risk reduction, and shares Black Hat 2026 insights on AI agents as a new attack surface, introducing the concept of 'intent collusion' and underscoring the critical need for foundational security principles like least privilege.

2026 Cost of a Data Breach Report: AI Is Changing Cybersecurity

2026 Cost of a Data Breach Report: AI Is Changing Cybersecurity

The 2026 Cost of a Data Breach Report reveals how AI is transforming cybersecurity, accelerating both attack sophistication and defense capabilities. It highlights rising breach costs, persistent vulnerabilities like phishing and ransomware, and the critical need for organizations to leverage AI and automation to reduce financial impact, improve response times, and strengthen overall security posture against AI-driven threats and future risks like quantum computing.

You Didn't Ship a Bug. You Just Wrote It for a Human. - Ravi Madabhushi, Scalekit

You Didn't Ship a Bug. You Just Wrote It for a Human. - Ravi Madabhushi, Scalekit

Ravi Madabhushi details how existing infrastructure, designed for human users, fails AI agents, leading to issues like rate limits and over-permissioning. He argues for treating agents as first-class principals with fine-grained, context-aware authorization and robust visibility to prevent non-deterministic and potentially rogue behaviors.

Why AI Agents Break Zero Trust at the Last Mile

Why AI Agents Break Zero Trust at the Last Mile

AI agents introduce a critical security gap when connecting to legacy enterprise systems, known as the 'agentic last mile identity problem'. This summary explains how losing user identity, context, and delegation breaks zero-trust principles and outlines a solution using a policy-driven vault to manage access and issue short-term credentials.

Agentic Consent Explained: How AI Agents Act Safely and Responsibly

Agentic Consent Explained: How AI Agents Act Safely and Responsibly

Grant Miller from IBM explains Agentic Consent, a dynamic framework for governing AI agents. The model moves beyond static permissions, using identity, context, and just-in-time user prompts to ensure AI agents act with, not instead of, their human counterparts, enabling trust and safety as autonomy scales.

Identity for AI Agents - Patrick Riley & Carlos Galan, Auth0

Identity for AI Agents - Patrick Riley & Carlos Galan, Auth0

This session from Okta and Auth0 introduces a comprehensive framework for securing AI agents, covering identity establishment, delegated API access via Token Vault, user consent for risky operations using Asynchronous Authorization (CIBA), and integration with MCP servers.