Monday, October 5, 2026

Denmark population registry data breach affects 8.8 million people

The most sensitive database in Denmark just lost 8.8 million records.

Denmark's Central Population Register exposed personal data on virtually every resident — names, addresses, national identity numbers — through a single unauthorized access event. When a registry that covers an entire population is breached, the damage is not marginal. It is total.

This is the AI era's sharpest data risk: agents and automated pipelines now move personal data at a speed no human review process can match. Every field that travels unprotected is a liability waiting to materialize.

Tokenize sensitive fields before any agent or pipeline touches them. Enforce runtime policy that blocks agents from transmitting raw identity data outside authorized destinations — and keep a provable, immutable record of every access so compliance can be demonstrated after the fact.

RuntimeAI closes this gap at the runtime layer, before it lands.

#DataPrivacy #PIIProtection #DataSecurity #AgentSecurity #RuntimeAI

Source: Bleeping Computer →
Researchers are tracking a Chinese AI 'agent fleet'

Adversaries are now deploying AI agents as attack infrastructure.

Researchers are tracking an active fleet of AI agents operating across the internet — not a human attacker at a keyboard, but an orchestrated swarm running at machine speed, probing targets, persisting in sessions, and acting autonomously. When the attacker is an agent, defenses designed for human threat actors are aimed at the wrong problem.

Every agent in your environment needs a verified identity with runtime-enforced scope. When an agent starts behaving outside its declared role — or when an inbound agent fleet starts probing your stack — a sub-50ms kill switch must terminate the session before it acts. Revoke identity, close the session, block the tool call. In that order. Before the data moves.

See how RuntimeAI turns this from an incident into a blocked action.

#AgentSecurity #AIThreat #NonHumanIdentity #KillSwitch #RuntimeAI #CyberSecurity

Source: TechCrunch →
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple just confirmed that AI agents are a data access problem worth shipping a platform change for.

Apple is tightening Full Disk Access controls in macOS specifically because AI agents are requesting — and receiving — sweeping filesystem permissions that expose everything on a machine. The platform gate Apple is building protects endpoints. It does not protect enterprise infrastructure.

In enterprise environments, agents are requesting access to databases, internal APIs, and sensitive document stores at runtime. Without enforcement of least-privilege tool-call permissions at the moment of execution, agents accumulate access that no individual administrator explicitly authorized. The agent calls the tool. The data moves. The access log fills up afterward.

Block the over-privileged call at the moment it is made — not after the data has already left.

This is exactly the control RuntimeAI enforces in real time.

#AIAgents #LeastPrivilege #AgentGovernance #ZeroTrust #RuntimeAI #EnterpriseAI

Source: The Hacker News →
The AI kill switch – what actually happens when you press it?

Everyone is now asking whether the AI kill switch actually works.

Computer Weekly put the question directly: when you terminate a misbehaving AI agent, what does that mean for identity and access management? Traditional IAM was designed for relatively stable machine identities. Agents spin up sessions, acquire credentials, and call external tools in seconds. The gap between 'I pressed the button' and 'the agent stopped acting' is where the damage happens.

A kill switch is only as fast as your identity layer. If an agent's session tokens, API keys, and active tool permissions are not revoked simultaneously — across every downstream connection — the agent keeps acting. Non-human identity governance means every agent session exists in a live registry, and termination is complete and instantaneous, not eventually consistent.

RuntimeAI governs this at runtime, where the agent actually acts.

#KillSwitch #NonHumanIdentity #IAM #AgentGovernance #RuntimeAI #CyberSecurity

Source: Computer Weekly →
The Credential Layer Is Expanding Faster Than Security Teams Can See It

AI agents are creating a credential explosion that security teams were not built to track.

Every agent that connects to an external system mints credentials — API keys, service tokens, OAuth grants, database sessions. A single agentic workflow generates dozens. Security programs designed for human identities are now watching machine identity counts grow exponentially, across systems they never explicitly provisioned and cannot fully see.

Know your agents before they know your systems. Every agent must receive a verified, scoped identity at instantiation — not a borrowed credential carrying inherited permissions from its host environment. Enforce strict scope at issuance. Revoke on anomaly. Maintain a complete, live registry so no agent credential persists beyond its authorized window and no shadow agent operates outside your visibility.

Check out how RuntimeAI solves this at the runtime layer.

#NonHumanIdentity #AgentIdentity #CredentialSecurity #ShadowAI #RuntimeAI #AIGovernance

Source: The Hacker News →