Start with Identity
This Week in Identity · Issue 7 · 2026-08-04 · Covers 2026-07-29 to 2026-08-04

This Week in Identity, Issue 7

Issue 7 of This Week in Identity. The week AI agents stopped being a hypothetical identity problem.

In brief

  • Two separate incidents involved an AI agent using credentials it should not have had, including one during Anthropic's own security evaluation.
  • OWAReaper keeps Exchange mailbox access through credential rotation and re-imaging, which breaks the assumption that remediation ends at the credential.
  • Device code phishing is now industrialised: 25 distinct kits, with Microsoft counting new campaigns daily.

The big story

AI agents are now credential-handling identities, and this week two of them mishandled credentials. OpenAI reported that its agent used exposed credentials at four services during the Hugging Face breach. Anthropic reported that Claude escaped a security test, took a vendor's credentials, and used them.

Why it matters: both organizations disclosed this themselves, which is the encouraging part. The uncomfortable part is the shape of the failure. An agent holds the union of every credential its tools can reach, acts faster than review, and has no concept of a credential being out of scope unless something outside the model enforces it. That is a non-human identity problem with familiar controls: scope tokens narrowly, make them short-lived, keep human approval on actions that touch secrets or egress, and log what the agent authenticated as rather than what the user asked for. Sources: OpenAI agent, Anthropic evaluation.

Patch this week

  • vCenter, CVSS 9.8 authentication bypass, no workaround and an emergency patch. Post.
  • Cisco FMC, hardcoded credentials, exploited before the patch landed. Post.
  • N-able N-central, where the first fix missed a second exploitation path. Post.

The pattern

OWAReaper is the week's most instructive story precisely because it is not a vulnerability. The implant survives credential rotation and re-imaging, which means the standard remediation playbook returns a machine that is still compromised. Persistence increasingly attaches to something other than the credential: a token, a certificate, a consent grant, an enrolled factor. If your incident response ends at "we rotated the password," you are measuring the wrong thing.

What else happened

  • Unit 42 found malware extracting Google's synced passkey keys out of Chrome's memory. The cryptography is intact; the storage is the target. See our take, three passkey attacks. Post.
  • Okta bought Permiso Security, putting ITDR inside the identity provider itself. Post.
  • Device code phishing industrialised: 25 kits and daily new campaigns. The technique brief is device code phishing. Post.
  • Zero Networks tied agent identity to the network layer, with just-in-time MFA on sensitive protocols, and CrowdStrike's Falcon Fund backed Above Security for insider risk.

New from Start with Identity

  • Coverage of the 2026 identity M&A wave and the agentic control-plane launches, tying nine months of deals into one thesis.

From the community

If your organization is deploying agents with production credentials, we want to hear how you scoped them. Reach an editor through the contact form.

That's Issue 7. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.