Recent analyses highlight that the most significant cybersecurity losses in 2025 stemmed from identity and OAuth token abuse, rather than high-profile zero-day vulnerabilities. Attackers leveraged AI to scale social engineering, phishing, and OAuth consent abuse, leading to widespread incidents across logistics, manufacturing, and other sectors. The rapid adoption of AI in enterprise environments has expanded the attack surface, with 99% of surveyed organizations experiencing at least one attack on their AI systems in the past year. The proliferation of GenAI-assisted coding has further outpaced security teams’ ability to secure production environments, compounding risk.
Security leaders are increasingly concerned about the misalignment between teams, tools, and workflows, which exacerbates the impact of these AI-driven threats. Effective management of non-human identities (NHIs), such as machine credentials and tokens, is now critical, especially in cloud and SaaS environments. The need for robust governance, visibility, and context-aware controls is underscored by the growing sophistication of attacks targeting both human and machine identities. Organizations are urged to prioritize identity and secrets management, as well as to adapt their security strategies to address the evolving risks introduced by AI and automation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CSO Online published an analysis of generative AI risk, emphasizing governance, human oversight, and the use of frameworks such as NIST AI RMF, CSA AI Model Risk Management Framework, and the AI Control Matrix.
Alpha Hunt published a 2025 retrospective arguing that the year's biggest losses came from stolen tokens, OAuth abuse, identity and SaaS attacks, and edge-device weaknesses rather than major zero-day events.
Palo Alto Networks released its State of Cloud Security Report 2025, reporting widespread attacks on AI systems, rising API and IAM weaknesses, and calling for consolidated cloud and SOC operations with agentic security approaches.
Security Boulevard published an article describing agentic AI as a way to improve management of non-human identities in cloud environments, especially for the travel industry, through automated and context-aware security operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.alphahunt.io
Open sourcepaloaltonetworks.com
Open sourcecsoonline.com
Open sourcesecurityboulevard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.