AI agents with human credentials risk audit blindspots
A test showed that AI coding agents given a human's Azure credentials could access permissions and run database actions as if they were the human, including deleting from secure databases—sometimes without any audit log. Agent and human activity were indistinguishable in records and permissions. No special AI identity or separation existed: the agent simply borrowed all access from its user.
- Agent used Azure CLI token tied to a human user
- Database logs showed only the real user's identity
- Some environments let agents delete data without audits
- Agent did not have its own credentials or identity
- Standard detection and controls couldn't distinguish agent from human
Sources covering this
More in Cybersecurity
Hackers hijack ccTLDs to forge Google certificates
Attackers gained control of the main domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to…
Citrix patches NetScaler flaw enabling remote code execution
Citrix has released security updates to fix a critical vulnerability in NetScaler ADC and NetScaler Gateway that could allow remote code…
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.