Fortra disclosed eight vulnerabilities in its BoKS privileged-access manager, three of them critical and one rated CVSS 9.9. Because the predictable passwords can be verified offline, applying the fix does not retire service-account credentials an attacker may already hold.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Fortra patched CVE-2026-79901, a CVSS 9.9 BoKS keytab flaw that lets any authenticated Active Directory user rebuild Unix service-account passwords offline. Patching replaces the generator, but passwords it already minted stay predictable until rotated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence50
Microsoft's accounts posture assessment lists every Active Directory user account with no logon in the past 90 days and refreshes the score every 24 hours. Service accounts are excluded from that list.
Publishers:docs.microsoft.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence66
The two September 15 disclosures describe a padding oracle and a SAML assertion wrapping bypass in Secret Server's pre-login code path, both reachable without credentials and both already closed in the August build.
Reality
- Evidence55
- Adoption28
- Hype gap+35
- Incentives55
- Confidence47
Delinea scored CVE-2026-15640 at 9.5 on CVSS v4 for on-prem Secret Server 10.5.0 through 12.1.3, and 12.2.7 is the only listed build that also clears the padding oracle and the FIDO2 registration bug.
Publishers:delinea.com
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap−8
- Incentives74
- Confidence70
Okta wants entitlements for AI agents and workloads evaluated continuously instead of recertified on a schedule, on the argument that approvals accumulate and access changes in the gaps between reviews.
Reality
- Evidence30
- Adoption14
- Hype gap+38
- Incentives76
- Confidence44
The new controls compare an agent's runtime behaviour against its authorized scope and can revoke the credentials underneath it. The 57% unmanaged-identity figure behind the pitch is Orchid's own, and neither publisher gives the method.
Reality
- Evidence28
- Adoption14
- Hype gap+38
- Incentives88
- Confidence62
A guidance post on dev.to argues you cannot catch remote support abuse by identifying the binary. The eight signals it recommends instead all lean on baselines most teams have never written down, and that is where the cost sits.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+28
- Incentives78
- Confidence58
At Fal.Con 2026 CrowdStrike said each AI agent will get a cryptographically verifiable identity and short-lived brokered access in place of a borrowed human credential. Coverage is whatever discovery finds.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives88
- Confidence46
The mechanism itself is roughly a week of work, using software that already ships with OpenSSH. What follows is harder: custody of a single key that opens every host, and an issuance flow whose requirements keep arriving.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+15
- Incentives80
- Confidence40
The deal completed on February 11, with identity security named a core pillar of platformization. CyberArk stays standalone for now, which is what every acquired platform is told first.
Publishers:paloaltonetworks.com
Reality
- Evidence34
- Adoption31
- Hype gap+44
- Incentives92
- Confidence46
BeyondTrust's Morey Haber counts a 466.7% year-over-year rise in AI agents inside enterprises. They authenticate, hold privileges and move data, and insider-threat programs still assume a human.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+42
- Incentives85
- Confidence52
The company extended just-in-time access, live session monitoring and device trust to Linux workstations this month, treating the laptop as production infrastructure rather than a trusted edge.
Reality
- Evidence28
- Adoption14
- Hype gap+32
- Incentives78
- Confidence42