Enterprise adoption of AI agents is rapidly expanding the number of non-human identities inside corporate environments, with organizations increasingly running mixed stacks of coding assistants, writing tools, enterprise search, and agentic systems rather than relying on a single provider. Reporting based on Okta sign-on data from more than 20,000 organizations says each added AI platform brings more logins, secrets, tokens, service accounts, and permissions, while many companies still authorize agents with static API keys, OAuth apps, shared human accounts, or other weakly governed credentials that reduce auditability and increase the risk of over-permissioned access and orphaned accounts.
Security reporting and industry data indicate that those governance gaps are already translating into higher exposure. The articles cite the UNC6395 campaign, in which attackers allegedly abused a trusted OAuth token linked to Salesloft's Drift chat integration to pivot through Salesforce environments and obtain additional secrets including AWS credentials and Snowflake tokens, showing how machine identities can be exploited without a software flaw. A 2026 identity security report also found a 43% breach rate among organizations reporting AI-driven identity growth, versus 11% where AI had not significantly expanded identity counts, prompting calls for continuous inventory, clear ownership, least-privilege controls, lifecycle management, audit logging, and Zero Trust enforcement for AI agents and other machine identities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The cited 2025 UNC6395 campaign allegedly abused a trusted OAuth token tied to Salesloft's Drift chat integration to move across Salesforce environments and obtain additional secrets, including AWS credentials and Snowflake tokens.
The Okta-based analysis says enterprise AI usage evolved from autocomplete to chat to agents, with agentic workflows accelerating in spring 2025 as organizations adopted broader AI tool stacks.
OWASP released its Top 10 for Agentic Applications for 2026, a globally peer-reviewed framework outlining critical security risks affecting autonomous and agentic AI systems. The guidance was developed with input from more than 100 experts and is positioned as practical security guidance for organizations deploying AI agents.
According to the Okta sign-on data analysis, Anthropic overtook OpenAI in enterprise accounts in March 2026, reflecting a shift in enterprise AI platform adoption.
NIST's Center for AI Standards and Innovation announced the AI Agent Standards Initiative to support secure, trusted, and interoperable adoption of autonomous AI agents. NIST said the effort would coordinate with federal partners and solicit public input on AI agent security, identity, authorization, and sector-specific adoption barriers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceupwind.io
Open sourcecysecurity.news
Open sourcecysecurity.news
Open sourcehelpnetsecurity.com
Open sourcegenai.owasp.org
Open sourcenist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.