Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
OpenAI's Sign in with ChatGPT lets Plus and Pro users run an app's AI requests on their own plan, up to a weekly cap they set per app. That cap reserves none of the user's quota, so builders still need their own API key for any request the plan cannot cover.
Reality
- Evidence55
- Adoption30
- Hype gap+5
- Incentives30
- Confidence50
GitHub let npm trusted publishing move dist-tags with short-lived OIDC credentials on 2026-09-30, behind a permission that ships switched off. It closes the gap that sent teams back to a long-lived token just to point latest at a new release.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Authorizer, a self-hosted open-source auth server, drops files a user may not see before an AI assistant's vector search scores them. Teams can run that check inside their own login server, though its limits on AI agents rest on the maintainers' word.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Trusted publishing swaps a stored npm token for a short-lived OIDC one, and it needs npm CLI 11.5.1, Node 22.14.0 and a hosted runner. The CLI falls back to the old token whenever the OIDC path is absent.
Publishers:docs.npmjs.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives78
- Confidence62
Red Hat's own upgrade guide names six environment decisions and three ways to run Ansible Automation Platform 2.7. It says the job can take an afternoon or several weeks, and RPM-based 2.4 and 2.5 installs sit at the long end.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives78
- Confidence60
SAML's security rests on XML signature validation, and most fielded implementations hand that job to libxmlsec. Trail of Bits says that dependency is the reason to deprecate the protocol and move SSO to OpenID Connect.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence55
RuntimeWire's comparison of two shipped Codex desktop builds found a second cloud path whose new environments start at package-manager network access, then take on Tailscale keys, proxy-delivered secrets and OIDC cloud identities.
Reality
- Evidence62
- Adoption8
- Hype gap+9
- Incentives35
- Confidence58
A ZoomEye query counted hosts answering on Kubernetes' default API port on 2026-09-20. The write-up keeps the unit honest: a host that responded to one port query, with no authentication test behind the number.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−15
- Incentives40
- Confidence60
The SSM agent holds a connection out to AWS, OpenSSH rides it as a ProxyCommand, and EC2 Instance Connect pushes a key that sshd forgets after 60 seconds, so the security group ingress list can stay empty.
Reality
- Evidence45
- Adoption10
- Hype gap+28
- Incentives85
- Confidence40
In a dev.to write-up, Jorge RN traces the chain from a workload's own identity to an ephemeral OCI session token, where the authorization decision reads claims such as repository, workflow and branch.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence35
A dev.to design post puts a per-task scope check under every tool invocation and caps the agent's cloud credentials at fifteen minutes. The restrictions work by taking capability away from the model.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+30
- Incentives20
- Confidence45
TanStack's postmortem says 84 malicious versions went out across 42 packages on 2026-05-11 with no npm token stolen, because a release job restored a cache that an untrusted pull_request_target build had written.
Publishers:tanstack.com
Reality
- Evidence68
- Adoption45
- Hype gap+6
- Incentives65
- Confidence58
The typed authentication module and Netty's HTTP/3 support both arrive experimental in Ktor 3.6.0, while the changes that touch code you already wrote are two deprecations and one client Accept-header setting.
Reality
- Evidence62
- Adoption15
- Hype gap+34
- Incentives70
- Confidence60
The pattern treats each MCP tool invocation on Amazon Quick as an access event and checks MFA, country, group-to-role mapping and tool permission against claims Entra ID puts in the token. Configuring the identity provider is most of the work.
Reality
- Evidence54
- Adoption
- Insufficient
- Hype gap+18
- Incentives82
- Confidence58
Frederic Bull says his team processed just over nine times the vulnerability volume in a year without adding headcount and cut time to remediate by 5%, a self-reported figure with no absolute counts behind it.
Reality
- Evidence26
- Adoption22
- Hype gap+34
- Incentives58
- Confidence48
Varonis Threat Labs registered its own External Authentication Method in a test Entra tenant and served a copy of Microsoft's password prompt during the second factor. Every sign-in completed, and the passwords landed in a file.
Publishers:varonis.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence55
AWS's multi-Region replication copies a Cognito pool's configuration, hashed credentials and IdP settings into one other Region with eventual consistency. Only the primary accepts writes, so failover planning becomes a per-path decision.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+22
- Incentives85
- Confidence64
AgentCore Identity now hosts the redirect leg and keeps the tokens, and what you configure in exchange is an OIDC application in your corporate IdP, a service role, and AWS's callback URL inside your GitHub and Slack apps.
Reality
- Evidence62
- Adoption12
- Hype gap+8
- Incentives88
- Confidence55
EarthLink Network's in-house identity platform now settles administrator status in one function, on both token issue and refresh, using the group-name check its products were already applying, and the UI only displays the answer.
Reality
- Evidence45
- Adoption22
- Hype gap−10
- Incentives50
- Confidence40
Earlier coverage
- Draft ORKS spec hands revocation of a leaked API key to whoever finds it
Security · September 9, 2026 · 1 publisher
- A public OIDC client with PKCE replaces the cluster certificate that outlives its owner
Product · September 9, 2026 · 1 publisher
- A pull request comment triggered a trusted workflow that published ten malicious npm versions
Build · September 8, 2026 · 1 publisher
- Anonymisation trades away the property that made the test fixture useful
Build · September 8, 2026 · 1 publisher
- CSA's Agentic Trust Framework maps agent autonomy to an auth stack you already run
Product · September 6, 2026 · 1 publisher
- npm 10.8.2 publishes unauthenticated when you configure Trusted Publishing
Build · September 6, 2026 · 1 publisher
- NVIDIA routes every cluster's identity check through one session-owning gateway
Build · September 3, 2026 · 1 publisher
- GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs
Security · September 3, 2026 · 1 publisher
- Bedrock's Sydney and Melbourne GPT-5.6 endpoints delegate the processing Region to AWS
Build · September 2, 2026 · 1 publisher
- Someone has to own the authority chain before an agent's purchase order clears
Leadership · September 1, 2026 · 1 publisher
- TeamCity's new OIDC plugin turns your build server into the credential issuer
Build · September 1, 2026 · 1 publisher
- Google Cloud IAP fences staging for free until the client stops being a browser
Build · September 1, 2026 · 1 publisher
- Putting the deploy command next to the app leaves CI one verb to call
Build · August 31, 2026 · 1 publisher
- A missing attribute condition admits every identity its provider will vouch for
Build · August 31, 2026 · 1 publisher
- Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways
Build · August 27, 2026 · 1 publisher
- Kubernetes Secrets are a distribution problem, and the database is where it shows
Product · August 24, 2026 · 1 publisher
- One unvalidated region string sent signed AWS API calls to attacker.com
Product · August 24, 2026 · 1 publisher
- Dropping long-lived AWS keys is half an EKS migration; the cluster still gets a vote
Build · August 22, 2026 · 1 publisher
- Partition, not consolidation: what a 43-minute Jenkins queue actually cost
Build · August 21, 2026 · 1 publisher
- Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build
Security · August 21, 2026 · 1 publisher
- The /userinfo fallback that quietly made Auth0 a hard dependency on every request
Build · August 20, 2026 · 1 publisher
- Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model
Build · August 18, 2026 · 1 publisher
- trelix's most useful release detail is an exit code, not the audit log
Build · August 15, 2026 · 1 publisher