home.social

#machineidentity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #machineidentity, aggregated by home.social.

fetched live
  1. SPIFFE/SPIRE Exposed to Post-Exploitation Identity Misuse

    When a host is compromised, the damage runs deep: attackers can exploit identity mechanisms to access all authorized identities on that node, essentially collapsing machine identity and putting your entire system at risk. This is the stark reality of a SPIFFE/SPIRE security breach, where short-lived workload identities can become a…

    osintsights.com/spiffespire-ex

    #Spiffe #Spire #PostexploitationIdentityMisuse #MachineIdentity #Kubernetes

  2. 🎙️ On the Nexus Podcast, ClearVector Founder & CEO John Laliberte explores one of today's fastest-growing cybersecurity challenges: non-human identities (NHIs) and the role AI agents play in creating and managing machine identities across enterprise and critical infrastructure environments.

    Learn why identity visibility, detection, and governance are essential for reducing cyber risk as AI adoption accelerates.

    🎧 Listen to the full episode: nexusconnect.io/podcasts/nexus

    #Cybersecurity #AI #IdentitySecurity #NonHumanIdentities #CriticalInfrastructure #MachineIdentity

  3. 🎙️ On the Nexus Podcast, ClearVector Founder & CEO John Laliberte explores one of today's fastest-growing cybersecurity challenges: non-human identities (NHIs) and the role AI agents play in creating and managing machine identities across enterprise and critical infrastructure environments.

    Learn why identity visibility, detection, and governance are essential for reducing cyber risk as AI adoption accelerates.

    🎧 Listen to the full episode: nexusconnect.io/podcasts/nexus

    #Cybersecurity #AI #IdentitySecurity #NonHumanIdentities #CriticalInfrastructure #MachineIdentity

  4. 🎙️ On the Nexus Podcast, ClearVector Founder & CEO John Laliberte explores one of today's fastest-growing cybersecurity challenges: non-human identities (NHIs) and the role AI agents play in creating and managing machine identities across enterprise and critical infrastructure environments.

    Learn why identity visibility, detection, and governance are essential for reducing cyber risk as AI adoption accelerates.

    🎧 Listen to the full episode: nexusconnect.io/podcasts/nexus

    #Cybersecurity #AI #IdentitySecurity #NonHumanIdentities #CriticalInfrastructure #MachineIdentity

  5. Machine identities (service accounts, API keys, certificates) outnumber human identities by orders of magnitude in most orgs — yet board-level risk reporting still centers on human access. The attack surface is real, but so is the measurement gap: you can't govern what you don't count. #infosec #IAM #machineidentity
    scworld.com/analysis/the-invis

  6. It’s not just about economics anymore. Pricing is starting to shape how people behave. It looks like a response to a crisis, but it nudges people to use less or act differently. Over time, it sets expectations about what’s “normal” to consume. Less about policy and more about using price to guide behavior.

    visiontimes.com/2026/03/17/chi #MachineIdentity

  7. It’s not just about economics anymore. Pricing is starting to shape how people behave. It looks like a response to a crisis, but it nudges people to use less or act differently. Over time, it sets expectations about what’s “normal” to consume. Less about policy and more about using price to guide behavior.

    visiontimes.com/2026/03/17/chi #MachineIdentity

  8. Meta's HyperAgents paper: AI agents that rewrite their own approach based on what worked, develop persistent memory of target environments, and transfer meta strategies to new attack surfaces.

    PAM session management assumes a human. Credential rotation assumes human timelines. Machine identity governance hasn't accounted for identities that autonomously evolve their behaviour.

    arxiv.org/abs/2603.19461

    #AI #CyberSecurity #PAM #MachineIdentity

  9. Meta's HyperAgents paper: AI agents that rewrite their own approach based on what worked, develop persistent memory of target environments, and transfer meta strategies to new attack surfaces.

    PAM session management assumes a human. Credential rotation assumes human timelines. Machine identity governance hasn't accounted for identities that autonomously evolve their behaviour.

    arxiv.org/abs/2603.19461

    #AI #CyberSecurity #PAM #MachineIdentity

  10. Meta's HyperAgents paper: AI agents that rewrite their own approach based on what worked, develop persistent memory of target environments, and transfer meta strategies to new attack surfaces.

    PAM session management assumes a human. Credential rotation assumes human timelines. Machine identity governance hasn't accounted for identities that autonomously evolve their behaviour.

    arxiv.org/abs/2603.19461

    #AI #CyberSecurity #PAM #MachineIdentity

  11. Meta's HyperAgents paper: AI agents that rewrite their own approach based on what worked, develop persistent memory of target environments, and transfer meta strategies to new attack surfaces.

    PAM session management assumes a human. Credential rotation assumes human timelines. Machine identity governance hasn't accounted for identities that autonomously evolve their behaviour.

    arxiv.org/abs/2603.19461

    #AI #CyberSecurity #PAM #MachineIdentity

  12. ----------------

    🔐 Identity (AI & Cloud-Native)

    Overview

    The article documents a shift in the enterprise attack surface: adversaries are increasingly targeting machine identities and service-level credentials rather than human accounts. Notable examples cited include VoidLink, which specializes in harvesting credentials, ShadowRay 2.0, which exploited an unauthenticated AI framework, and LangFlow, which retained service credentials and created a “master key” effect for connected services.

    Key findings and numbers
    • Machine identities outnumber human identities by an average ratio of 82:1 (Rubrik Zero Labs).
    • A Cloud Security Alliance survey found 44% of organizations authenticate AI agents with static API keys, while only 28% can trace agent actions back to the human who authorized them; nearly 80% cannot currently report what deployed AI agents are doing or who is responsible.
    • SPIFFE and SPIRE are presented as the primary industry response for workload identity: they issue short-lived, automatically rotating credentials tied to verified workload attributes, reducing the value of long-lived secrets.

    Where current systems fall short
    • The piece emphasizes that SPIFFE/SPIRE were designed for traditional workload interactions; they can mitigate lateral movement and make alerts attributable when workloads carry verifiable identities. However, these systems are less effective for modern autonomous AI agents that make decisions, delegate tasks, and often authenticate with static credentials.
    • The result is an expanding risk surface: AI agents and machine identities broaden potential impact from breaches because credentials often are created informally, rarely rotated, and lack centralized governance.

    Implications reported (factual)
    • Attackers are not primarily “breaking in” but are leveraging logged-in identities belonging to machines and services.
    • Short-lived workload credentials are described as an effective technical control against credential harvesting tactics used by malware like VoidLink.

    🔹 VoidLink #SPIFFE #LangFlow #ShadowRay #machineidentity

    🔗 Source: blogs.cisco.com/security/ident

  13. Interview with Dino DiMarino, CEO at AppViewX, on why machine identities are outpacing user identities in critical infrastructure.

    🔐 “You can’t plan for post-quantum cryptography without an accurate cryptographic bill of materials.”

    Full interview: technadu.com/explaining-why-ce

    #CyberSecurity #MachineIdentity #PKI #ZeroTrust #CryptoAgility

  14. Interview with Dino DiMarino, CEO at AppViewX, on why machine identities are outpacing user identities in critical infrastructure.

    🔐 “You can’t plan for post-quantum cryptography without an accurate cryptographic bill of materials.”

    Full interview: technadu.com/explaining-why-ce

    #CyberSecurity #MachineIdentity #PKI #ZeroTrust #CryptoAgility

  15. Interview with Dino DiMarino, CEO at AppViewX, on why machine identities are outpacing user identities in critical infrastructure.

    🔐 “You can’t plan for post-quantum cryptography without an accurate cryptographic bill of materials.”

    Full interview: technadu.com/explaining-why-ce

    #CyberSecurity #MachineIdentity #PKI #ZeroTrust #CryptoAgility

  16. Is having a new machine-id after every boot a bad idea if using in ? Why? Or is it precisely a good thing? Thanks for any advice.

  17. Is having a new machine-id after every boot a bad idea if using #impermanence in #nixos ? Why? Or is it precisely a good thing? Thanks for any advice. #machineidentity

  18. Is having a new machine-id after every boot a bad idea if using #impermanence in #nixos ? Why? Or is it precisely a good thing? Thanks for any advice. #machineidentity

  19. Is having a new machine-id after every boot a bad idea if using #impermanence in #nixos ? Why? Or is it precisely a good thing? Thanks for any advice. #machineidentity

  20. Is the most important security domain -- identity -- getting lost in all the AI noise?

    You can't implement your zero trust strategy without identity. And, with machines outnumbering humans in most enterprises, ranging from 7 to 45 more machines than humans, securing machine identities is paramount to secure your organization.

    Securing machine identities is the focus of @TokenSecurity which just raised $7M seed funding.

    #security #cybersecurity #identity #identitysecurity #machineidentity #funding #zerotrust

    siliconangle.com/2024/05/08/to

  21. Is the most important security domain -- identity -- getting lost in all the AI noise?

    You can't implement your zero trust strategy without identity. And, with machines outnumbering humans in most enterprises, ranging from 7 to 45 more machines than humans, securing machine identities is paramount to secure your organization.

    Securing machine identities is the focus of @TokenSecurity which just raised $7M seed funding.

    #security #cybersecurity #identity #identitysecurity #machineidentity #funding #zerotrust

    siliconangle.com/2024/05/08/to

  22. Is the most important security domain -- identity -- getting lost in all the AI noise?

    You can't implement your zero trust strategy without identity. And, with machines outnumbering humans in most enterprises, ranging from 7 to 45 more machines than humans, securing machine identities is paramount to secure your organization.

    Securing machine identities is the focus of @TokenSecurity which just raised $7M seed funding.

    #security #cybersecurity #identity #identitysecurity #machineidentity #funding #zerotrust

    siliconangle.com/2024/05/08/to