Securing AI Agents via Zero Trust and Non-Human Identity NHI Controls
Autonomous AI agents are vulnerable to Indirect Prompt Injection (IPI), where adversarial instructions embedded in third-party data—such as emails or web content—bypass probabilistic guardrails to execute unauthorized tool calls. This leads to "excessive agency," enabling credential theft, unauthorized data exfiltration, and lateral movement. Mitigation requires transitioning from linguistic constraints to deterministic Zero Trust architectures. By treating agents as Non-Human Identities (NHI), organizations can enforce granular OAuth scopes, utilize short-lived OIDC tokens, and implement hard Access Control Lists (ACLs) to isolate agentic workloads and prevent unauthorized API interaction.
Kali365 Phishing Kit: MFA Bypass Targeting Microsoft 365, AWS, and Okta
The FBI has issued a critical alert regarding the Kali365 phishing kit, a sophisticated tool designed to compromise enterprise cloud environments. Utilizing Adversary-in-the-Middle (AiTM) techniques, the kit intercepts authentication traffic to harvest credentials and steal active session tokens, effectively bypassing multi-factor authentication (MFA) protocols. The campaign specifically targets Microsoft 365 (Outlook, Teams, OneDrive), Amazon Web Services (AWS), and Okta identity providers. Successful exploitation grants threat actors deep access to corporate communications and critical cloud infrastructure, enabling large-scale data exfiltration and the compromise of organizational identity management systems.