AI | Security
Rogue AI Agents Needed Exposed Credentials to Breach Hugging Face
700 rogue AI agents breached Hugging Face through exposed credentials. What the incident reveals about AI agent identity security.
AI | Security
700 rogue AI agents breached Hugging Face through exposed credentials. What the incident reveals about AI agent identity security.
AI | Security
InfoSec | Machine IAM | Security
DevOps | Machine IAM | Security
Webinar
Control What AI Agents Do at RuntimeSee how Enterprise organizations secure AI agent access across MCP and leading AI frameworks with SecretlessAI™ and runtime controls.
AI | Security
Rogue AI Agents Needed Exposed Credentials to Breach Hugging Face700 rogue AI agents breached Hugging Face through exposed credentials. What the incident reveals about AI agent identity security.
This video, broadcast live from Black Hat USA, features a discussion on the challenges and best practices for securing agentic AI workloads within an enterprise environment.
AI | Security
AI Agents Security in Claude with AkeylessAI agent security usually stops at protecting credentials, but that's only half the problem. In a live demo with Akeyless, we gave a Claude Code agent full EC2 admin access, then tried to talk it into stopping a production server, even claiming CISO approval. Here's how Agentic Runtime Authority blocked it anyway, and why AI agent security has to govern actions, not just access.
InfoSec | Machine IAM | Security
Gartner Is Right That You Can’t Substitute WPM for PAM, So Stop Choosing Between ThemWorkforce password management (WPM) and privileged access management (PAM) tools both store credentials, but Gartner's July 2026 research concludes they cannot substitute for each other. WPM lacks privileged account discovery, automated service-account rotation, and session recording. PAM is too complex and costly for everyday workforce use. The Akeyless Identity Security Platform delivers purpose-built WPM and modern PAM on a single control plane, avoiding the substitution risk Gartner warns about.
DevOps | Machine IAM | Security
Not All Just-in-Time Access Is Created Equal: Why JIT Architecture MattersJust-in-Time isn't just about temporary credentials. It's about eliminating standing privileges without introducing operational complexity, infrastructure overhead, or new trust assumptions. Here's how Akeyless approaches JIT differently, and why the underlying architecture matters just as much as the credentials themselves.
The modernization initiative improved operational resilience while providing a scalable security foundation to support the retailer's continued digital transformation.
DevOps | Machine IAM | Security
Shai-Hulud Returns: The npm Worm That Only Works Because Your Secrets Are Standing StillThe recent Shai-Hulud supply chain attack demonstrates a fundamental shift in how attackers compromise organizations. Rather than exploiting software vulnerabilities, the malware targets what already exists on developer workstations and CI/CD systems: long-lived credentials. From .env files and cloud credentials to HashiCorp Vault tokens and AI coding assistants, the attack succeeds because secrets remain static, discoverable, and reusable. The lesson is clear: reducing standing privileges, adopting just-in-time credentials, and moving toward secretless authentication dramatically reduces the attacker's blast radius.
Security
From Secrets Sprawl to Secretless Authentication: The Five Phases of Modern Identity SecuritySecretless authentication eliminates the permanent credential applications use to access a secrets platform. Explore the journey from centralized secrets and automated rotation to workload identity federation through a live Kubernetes demo.
Webinar
Securing AI Agents in Claude with AkeylessSee how Akeyless Agentic Runtime Authority enables secure AI agent access with just-in-time credentials, runtime policy enforcement, and full auditability.
DevOps | Machine IAM | Security
npm Just Killed the Skeleton Key: What It Means for Every Other Credential You OwnGitHub's new 2FA rules close npm's biggest attack path. Learn what changed, why it happened, and what it means for every credential in your CI pipeline.
AI | Machine IAM | Security
Understanding the AI Agent Security Ecosystem: Roles, Responsibilities, and Where Runtime Authority FitsAs enterprises deploy AI agents, an entirely new security ecosystem is emerging. AI discovery platforms, MCP gateways, workforce AI governance platforms, automation platforms, and runtime authorization solutions all promise to secure AI agents—but they solve fundamentally different problems. Understanding where each category fits is becoming just as important as choosing the right products.
Ready to get started?
Discover how Akeyless simplifies secrets management, reduces sprawl, minimizes risk, and saves time.
Take a self-guided tour of our top features.
See the platformLearn what Akeyless can do for your team.
Talk to an expert