News – June 16, 2026

News for today:

  • [CrowdStrike] Continuous Identity for AI Agents. CrowdStrike added a new capability to its Falcon Next-Gen Identity Security solution (does this make it the Next-Next-Gen solution?) which gives continuous identity for AI agents. AI agents invoke tools, access sensitive data, call APIs, and delegate to sub-agents at machine speed with system-level privilege. Legacy access models were never built to control this. Continuous Identity for AI Agents – powered by technology from CrowdStrike’s recent acquisition of SGNL – dynamically grants, denies, and revokes access based on real-time risk, eliminating standing privileges entirely. CrowdStrike
  • [Zero Networks] Lateral movement exposure research. New research from Zero Networks looks at the realities of lateral movement within enterprise networks. Key finding (ouch): 80% of enterprise servers are reachable from anywhere inside the network – creating greenfield conditions for ransomware, operational disruption, and full-environment compromise. This internal traffic, known as East West traffic, represents more than 70% of a company’s communications – yet it remains unprotected. To drive home the point of an unprotected blast radius, Zero released a free Breach Map tool for security leaders. Zero Networks
  • [SailPoint] We’re getting Entro. SailPoint announced its intent to acquire Entro, for its NHI and credential security capabilities; will be added to the SailPoint Agentic Fabric. As organizations rapidly deploy autonomous AI agents, complex cloud architectures, and programmatic workflows, today’s modern security demands are no longer defined by traditional perimeters. Instead, they are governed by who or what is accessing data, when, why, and under what conditions. By integrating Entro’s specialized capabilities to directly address the unique challenges of the AI era, SailPoint expects to further expand how customers easily identify, govern, and protect these high-risk assets from a single, unified platform. SailPoint
  • [1Password] We bought Apono! 1Password announced the acquisition of Apono, for its just-in-time access governance technology that works across people, machines, and AI agents. Apono makes a decision on each access request rather than relying on standing accounts: it evaluates the request against policy, then dynamically creates the account, role, or permission the task requires scoped to the task and time-bound in each platform’s native permissioning system (e.g., cloud IAM), and removes it automatically when the work is complete. Because access is created on demand and torn down afterward, there are no standing accounts or privileges to manage and it is seamless for teams to deploy and operate. 1Password
  • [1Password] New Credential Broker. 1Password introduced the 1Password Credential Broker, enabling a new way of enabling trusted access to credentials stored in 1Password for people, workflows, and AI agents. The 1Password Credential Broker extends the role of 1Password from storing secrets to brokering credentials for the humans, machines, and agents that need them. Instead of distributing long-lived secrets across tools and environments, organizations can keep credentials protected in 1Password and release only the approved credential, token, or access artifact to a trusted requester when work needs to happen. In private beta only. 1Password
  • [Saviynt] Agent Access Gateway updates. Saviynt updated its Agent Access Gateway, with new intent-aware capabilities. The new approach evaluates AI agent actions in real time based on identity, context, policy, and intent. If an action falls outside approved boundaries, Saviynt can block it and generate an audit event at runtime. With IARA [Intent-Aware Runtime Authorization], organizations can protect sensitive resources from unintended or unauthorized actions. There’s also other new identity security goodness for identity governance and security posture. Saviynt
  • [RSA] Authenticating help desk callers. RSA added new capabilities to its RSA Help Desk Live Verify service, for verifying third-parties without an authenticator, e.g., contractors, partners. The update extends … protection beyond the immediate workforce to now include contractors, partners, temporary employees, and users without a registered authenticator. The new ID Verification capability, powered by ID Dataweb, allows users without a registered authenticator to verify their identity through a government-issued document and other forms of identification. Organizations can also use the RSA ID Plus / ID Dataweb integration for secure enrollment, identity verification, and other workflows to assure new users’ identities from the start. GA scheduled for late summer 2026. RSA

Discover more from Osterman Research

Subscribe now to keep reading and get access to the full archive.

Continue reading