Security and platform experts warned that enterprise AI agents are creating identity and access risks that traditional governance models do not adequately cover. In one cloud audit, a fintech firm's LLM agent service account was found with excessive AWS permissions including s3:* and iam:PassRole, even though the agent only required limited access to a single bucket and model invocation. Researchers said non-human identities tied to agents have become a major blind spot because prompt injection and memory-layer abuse can expose credentials, enabling attack paths that move from token theft to lateral movement and persistence across production environments.
Across the industry, practitioners are pushing for stronger controls built around unified identity fabrics, short-lived credentials, delegated authority, and continuous mapping of relationships among humans, applications, APIs, service accounts, and other agents. They also argued that enterprise deployments need structural least privilege and better auditability, with capability-scoped MCP connections favored over broad direct API integrations and brittle allowlists. The goal is to prevent agents from inheriting unchecked privileges, reduce orphaned or long-lived machine identities, and preserve accountability when autonomous agents create other agents or continue operating after their human owners change roles or leave the organization.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Panelists in an SC Media webcast said autonomous AI agents create dynamic inheritance chains across humans, applications, service accounts, APIs, and other agents, making traditional identity governance insufficient. They recommended a unified identity fabric with cryptographic trust, ephemeral credentials, delegated authority, and dynamic authorization to govern AI agents.
A cloud security audit at a fintech company uncovered an AI agent service account with excessive AWS permissions, including s3:* and iam:PassRole, even though the agent only required limited access to one bucket and Bedrock model invocation. The finding was presented as evidence that non-human identities used by AI agents are a major security blind spot.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceteiss.co.uk
Open sourcemicrosoft.com
Open sourcescworld.com
Open sourcethenewstack.io
Open sourcescworld.com
Open sourcecodeby.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.