>samit_hota
Back to security news

Security News · SN-2026-468

INFORMATIONALOPEN

New Infosec Releases Address AI Agent Drift, Exposure Management, and TPRM

Affected: Akeyless · Orchid Security · Scytale · Securin

Samit Hota·
#news#vulnerability-disclosure#new

Enterprise security architecture is increasingly pivoting toward managing non-human identity risks and automated attack surface validation. Recent market releases, including the general availability of the Securin Platform for exposure management, Orchid Security AI agent kill switches, and the Akeyless Agentic Runtime Authority, highlight how vendors are tackling these modern execution and exposure vectors. Alongside these releases, Scytale has expanded its governance capabilities with automated third-party risk controls.

Together, these tooling updates reflect a broader operational shift across enterprise SOCs: security teams can no longer rely on static permissions, annual vendor assessments, or isolated vulnerability scans when autonomous agents and complex identity relationships operate at machine speed.

Mitigating Autonomous AI Agent Risks and Identity Drift

As enterprises deploy autonomous AI agents into workflow engines and production pipelines, these tools present a unique privilege escalation paradigm. AI agents rarely need to exploit traditional memory corruption vulnerabilities or breach firewall perimeters to compromise systems. Instead, because agents interact with systems via valid application programming interfaces (APIs) and access tokens, they operate using legitimate permissions. When an agent experiences goal drift, prompt manipulation, or flawed reasoning, it can execute actions far beyond its intended functional scope within seconds without violating standard authentication guardrails.

This threat vector relies heavily on existing enterprise identity debt—a collection of hard-coded credentials, unmanaged authentication paths, orphaned service accounts, and overly permissive IAM roles. Once an agent accesses an environment, it inherits this implicit trust and can traverse these identity paths automatically.

Two newly released products specifically address this runtime challenge:

  • Akeyless Agentic Runtime Authority: Operating as a real-time identity control layer for AI agent actions, this newly generally available tool works on top of Akeyless SecretlessAI. While SecretlessAI acts as a credential protection layer that brokers system access without exposing underlying credentials to the agent, Runtime Authority introduces intent-based access control. Rather than relying solely on identity authentication, it inspects the actual intent of the agent’s proposed action at execution time, enforcing boundaries on what an authenticated agent is permitted to execute.
  • Orchid Security Readiness Controls: Orchid Security has introduced identity drift detection alongside application-level kill switches tailored for AI agents. The platform continuously monitors for instances where an agent’s behavior begins exceeding its intended baseline privileges. If an agent attempts to leverage latent identity debt across the enterprise, the application-level kill switch provides defenders with an immediate mechanism to terminate the agent’s session and halt unauthorized API execution.

Continuous Exposure Management and Attack Path Validation

Traditional vulnerability management workflows frequently stall under the sheer volume of CVE listings and high CVSS scores. Security operations teams routinely struggle to determine which identified vulnerabilities are genuinely exposed to untrusted networks, whether an exploit path exists from an entry point to sensitive target assets, and whether applied mitigation controls successfully remediate the risk.

Addressing these visibility gaps, Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management solution. The platform is structured around three core operational questions:

  1. What assets and vulnerabilities can an attacker actually exploit?
  2. Which exposed attack paths require immediate prioritization?
  3. Did the applied fix or compensating control verifiably close the exposure?

The platform consolidates attack surface discovery, threat intelligence, vulnerability management, offensive validation, and remediation tracking into a unified workflow. By integrating offensive validation directly into the remediation lifecycle, security teams can dynamically test attack paths rather than assuming that a patch or firewall rule has effectively mitigated exposure. This approach reduces noise by shifting focus from theoretical vulnerabilities to reachability and active exploitability.

Automating Continuous Third-Party Risk Management

Third-party risk management (TPRM) has historically functioned as a point-in-time compliance exercise, relying on annual self-assessment questionnaires, static SOC 2 report reviews, and spreadsheet tracking. However, dynamic cloud integrations and rapid vendor adoption render periodic reviews obsolete quickly, leaving organizations blind to mid-year supply chain compromises or security degradation at critical vendors.

To bridge this gap, Scytale has launched updated AI-powered TPRM capabilities within its Vendors module. The update converts traditional vendor risk workflows into a continuously updated intelligence engine. Scytale’s platform automates key aspects of the vendor oversight lifecycle:

  • Vendor Discovery: Identifying third-party tools and SaaS applications operating within the enterprise ecosystem.
  • Automated Risk Scoring: Evaluating vendor security postures dynamically based on continuous risk signals.
  • Evidence Collection: Gathering and mapping compliance artifacts across standard security frameworks automatically.

By continuously refreshing risk scores and compliance evidence, security and GRC teams maintain an updated inventory and risk posture for every third-party vendor operating within their footprint.

Enterprise Implementation Considerations

Organizations evaluating these security capabilities should align implementation with their specific architectural maturity:

  • For AI Agent Deployment: Ensure that non-human identities assigned to autonomous agents adhere to strict least-privilege principles. Implementing intent-based access constraints and runtime termination capabilities prevents automated systems from leveraging latent service account privileges.
  • For Exposure Management: Focus remediation resources on validated attack paths that link external attack surfaces directly to sensitive assets, moving away from pure CVSS-based patching queues.
  • For Supply Chain Governance: Transition vendor management programs away from manual, periodic review cycles toward automated evidence ingestion and continuous vendor scoring.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call