Two access control flaws in RabbitMQ expose OAuth client secrets and enable reconnaissance via queue metadata; patches are available for versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Claude receives its own service accounts and identities instead of access to personal user credentials, enabling admins to centrally and granularly define which tools and data each AI agent can use in which channels.
While network perimeter loses effectiveness as a primary protection layer, Zero Trust models offer an alternative but first require comprehensive transparency across all network actors.
Service desks are popular vectors for social engineering attacks because controls are weak and operational pressure on staff is high — a combination that demands training, process improvements, and technical controls.
The effective access of AI agents is not determined by IAM permissions alone, but by the interplay with firewall rules, cloud policies and microsegmentation — a policy governance task that most organizations systematically underestimate.