A Wire survey found that 61% of security leaders say access to shared files in Microsoft 365 often stays active far longer than intended, while more than a third struggle to even identify who currently has access to sensitive shared content. The report points to routine sharing habits—like adding freelancers to SharePoint folders or inviting new members into Teams channels—as common ways access quietly persists beyond its original purpose.
bleepingcomputer.com
· 2026-09-18
Cymphony, a New York- and Tel Aviv-based startup, raised a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, pushing its valuation above $100 million after a previously undisclosed Sequoia seed round. The company builds a 'workforce graph' that gives security teams visibility into which employees, AI agents, and other non-human identities can access sensitive systems and data.
techcrunch.com
· 2026-09-09
Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.
bleepingcomputer.com
· 2026-09-04
New research indicates that the anticipated surge in software vulnerabilities linked to AI-assisted coding tools may be more manageable than security experts initially feared. The findings suggest that enterprises adopting proper mitigation strategies can handle the increased volume of flaws without being overwhelmed.
darkreading.com
· 2026-09-02
Microsoft has identified a new ClickFix-style social engineering campaign called TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into pasting malicious commands into Windows Terminal or PowerShell. Once executed, the command triggers a multi-stage attack chain designed to give attackers a persistent foothold inside enterprise systems.
darkreading.com
· 2026-08-31
Box's chief information security officer, Heather Ceylan, warns that traditional identity and access controls—built for human users—are insufficient to manage AI agents that act autonomously at scale. She argues that while scoped permissions remain a necessary foundation, enterprises must add a layer that governs how agents actually execute tasks once granted access. Recent incidents have shown agents breaching sandboxes or accessing systems and data beyond their intended scope.
venturebeat.com
· 2026-08-31