❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 23 July 2026Main stream

Passkeys were supposed to replace passwords, but they're failing for the most predictable reason

23 July 2026 at 13:22

Passwords are a problem. Not only have they reached a point where a "strong" password is one no human can remember (much less remember dozens of them), but they simply aren't as secure as they need to be. Passkeys combine a public and private cryptographic key pair with local authentication such as a fingerprint or facial scan. The device can prove its identity beyond doubt, and the assumption is that only you can unlock it.

Microsoft 2.5: New security business chief Hayete Gallot on the company’s push into the agentic era

23 July 2026 at 10:43
Hayete Gallot, now executive vice president of Microsoft Security, speaks at a Microsoft event in France in 2024. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what we’re calling its β€œMicrosoft 2.5” era.

AI has had an impact on just about every tech-product category, but especially security. Attackers are using AI; customers are looking to defend with AI. The goalposts keep shifting. β€œAgentic security” is now the holy grail, and Hayete Gallot, the newly minted executive vice president of Microsoft Security, is leading the charge toward it.

Gallot, a 16-plus-year Microsoft veteran who rejoined the company in February after a 1.5-year Google detour, replaced Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual contributor focused on engineering quality.

β€œCustomers care about two things: solving for security and being able to afford it,” Gallot said when I asked during our interview this week why she came back to Microsoft.

β€œI am a problem solver. And an engineer at heart (and by training). Security is the most important problem right now β€” and Microsoft is the only place with all of the puzzle pieces to help our customers.”

Since her return, Gallot hasn’t been shy about shaking things up. As noted recently by The Information, at least nine corporate vice presidents who previously reported to Bell have left the company this year.

β€œWe’re making changes to ensure we’re in the best formation to go after this opportunity,” she acknowledged.

β€œI’m motivated by doing the right thing for our customers, my teams, and tech outcomes,” she said. β€œI like to move quickly: days and weeks, not months and years, learning through execution, iterating rapidly, and adjusting based on real customer signals.”

The company isn’t starting from scratch. As of 2021, Microsoft claimed security was a $10 billion business for the company. By 2023, security had reached a $20 billion annual revenue rate, officials said.

Those claims haven’t been without controversy. Microsoft has built a huge business in finding and fixing security problems which some customers felt were of the company’s own making.

Microsoft has a wide-ranging and rather unwieldy security portfolio, encompassing identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft introduced its Security Copilot set of AI analysis services that integrated with some of its existing security offerings. But a portal-based solution like Security Copilot doesn’t offer the kind of end-to-end coverage that an agentic security platform can, Gallot said.

The problem is that attackers are using agents, too. Customers need real-time insight into what’s happening in their environment, and the ability to act just as quickly, Gallot said.

Agentic security is about β€œtaking the signals and turning them into a graph that is useful,” Gallot said. β€œIf you’re trying to reason about 100 trillion signals, it’s not really effective.” The graph, she said, lets agents pick the right model for each threat and close the loop.

In practice, that means the system can quarantine a device or revoke access on its own, for example, rather than waiting for a human.

Microsoft’s core existing security products will continue to play a role as the landscape evolves, both spotting the problems and acting on them. Security Copilot isn’t going away in the process: β€œYou’ll have Copilot and you’ll have agentic security,” she said.

The company’s new Agent 365 β€œcontrol plane” β€” a central console for tracking every AI agent a company runs β€” fits in by letting customers see the β€œblast radius” of an agent, meaning everything a hijacked agent could reach, Gallot said. It’s similar in concept to Zero Trust, the β€œnever trust, always verify” security model that limited how far an attacker could get with a stolen employee login, but applied now to agents rather than people.

So what exactly is this β€˜agentic security’ thing? Microsoft has a whole website dedicated to the very topic.

Traditional AI security and agentic AI security are fundamentally different, Microsoft says. Agentic security doesn’t just protect models and training data; it also can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential positive and negative stakes are higher.

While AI has helped businesses make strides in finding and fixing vulnerabilities, it hasn’t gone much beyond that. Microsoft introduced its multi-model agentic scanning harness (MDASH) as its first step into the agentic security space, Gallot said.

The company used MDASH internally to boost finding and fixing Windows security issues, and it is now making it available to select customers in an expanded preview. MDASH will allow customers to use the best model for the right task to secure all different types of code bases, she said.

Microsoft is rumored to be readying a more comprehensive agentic security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI are offering security tools on their platforms, and dedicated security vendors are building their own agentic platforms.

Microsoft has the advantage of scale in the enterprise. The question is whether Gallot and her new leadership team can turn that scale and emerging AI tools into both a bigger business for the company and better protection for its customers.

Yesterday β€” 22 July 2026Main stream

FedRAMP and Identity Security: Why federal organizations are consolidating identity security platforms

Identity security consolidation helps federal agencies reduce risk, cut costs and strengthen Zero Trust by unifying governance, access and AI controls.

Β© Getty Images/Orhan Turan

Digital Identity and Cybersecurity Technology Concept

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face

22 July 2026 at 15:11
OpenAI made a mistake setting up what it called a β€œhighly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.

New Data Shows Suno Breach Affected 55M Accounts

22 July 2026 at 11:53

New data shows 55.3 million Suno accounts were affected in a breach exposing contact details, purchases, and partial payment card information.

The post New Data Shows Suno Breach Affected 55M Accounts appeared first on TechRepublic.

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

22 July 2026 at 12:47

OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.

Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.

At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.

Read full article

Comments

Β© Getty Images

❌
❌