Follow the latest coverage, related explainers and connected technology stories.
Microsoft explains how the Storm-3068 attack began with an account compromise through self-service password reset, then extended to Azure DevOps, development pipelines, and Kubernetes resources. The case highlights the importance of protecting identities, controlling deployment-pipeline permissions, and reviewing connections between development and cloud environments.
Microsoft explains that artificial intelligence does not create entirely new vulnerabilities as much as it accelerates the collection of known vulnerabilities and turns them into attack paths spanning identities, devices, applications, and systems. The company proposes a set of practical controls, including identity protection, least privilege, agent execution isolation, stricter remote access, and continuous reduction of exposure.
Maher Yamout warned that operating artificial intelligence systems without sufficient security assessment could open new attack paths, particularly when these systems receive broader privileges than they need or collect sensitive data. He called on organizations to reduce privileges, control internet access, and strengthen employee awareness of phishing and social engineering.
Nik Kale argues that securing AI agents should be built as a six-layer chain that begins with inventorying agents and defining their identities and authorization context before reaching policy enforcement through runtime gateways. He proposes a practical framework for testing readiness, with a focus on limited permissions, attributable logs, and a comprehensive shutdown path.