Security architectures must realign: agents require unique identities, strict access controls over models, data, and tools, plus central control points – otherwise uncontrollable shadow IT emerges with significant abuse potential.
German companies are increasingly switching their security providers and preferentially investing in AI security and Identity and Access Management, while integration and value for money dominate purchasing decisions.
Microsoft’s GDID helped investigators identify a cybercriminal, but technical details about the scope and sources of data collection remain unclear in the indictment and affect data protection assessments.
Russian threat actors exploit an OWA vulnerability to maintain mailbox access even after credential rotation, targeting critical infrastructure and government entities in the USA and Europe.
The CRA requires manufacturers from September 2026 onwards to report actively exploited vulnerabilities, demanding full transparency on machine identities and secrets in the supply chain earlier than the December 2027 deadline.
Nearly 25,000 publicly exposed BMCs are vulnerable through CVE-2013-4786, a 20-year-old flaw that grants attackers direct access to server hardware and potentially the entire management infrastructure.
Tengu combines hardware watchdog abuse with multiple persistence mechanisms into a self-protection system that circumvents Defender termination through forced reboots of compromised Linux devices.