Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityidentity-authentication-vulnerabilityphishing-campaign-intelligenceleaked-secret-api-key

AI-Driven Risks and Identity Abuse in Modern Enterprise Security

Updated 3mo agoFirst seen Dec 16, 20254 sources

Recent analyses highlight that the most significant cybersecurity losses in 2025 stemmed from identity and OAuth token abuse, rather than high-profile zero-day vulnerabilities. Attackers leveraged AI to scale social engineering, phishing, and OAuth consent abuse, leading to widespread incidents across logistics, manufacturing, and other sectors. The rapid adoption of AI in enterprise environments has expanded the attack surface, with 99% of surveyed organizations experiencing at least one attack on their AI systems in the past year. The proliferation of GenAI-assisted coding has further outpaced security teams’ ability to secure production environments, compounding risk.

Security leaders are increasingly concerned about the misalignment between teams, tools, and workflows, which exacerbates the impact of these AI-driven threats. Effective management of non-human identities (NHIs), such as machine credentials and tokens, is now critical, especially in cloud and SaaS environments. The need for robust governance, visibility, and context-aware controls is underscored by the growing sophistication of attacks targeting both human and machine identities. Organizations are urged to prioritize identity and secrets management, as well as to adapt their security strategies to address the evolving risks introduced by AI and automation.

Share:
AI-Driven Risks and Identity Abuse in Modern Enterprise Security
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 16, 20256mo ago

CSO Online outlines AI risk governance and security framework needs

CSO Online published an analysis of generative AI risk, emphasizing governance, human oversight, and the use of frameworks such as NIST AI RMF, CSA AI Model Risk Management Framework, and the AI Control Matrix.

Alpha Hunt publishes 2025 cyber loss retrospective on tokens and OAuth

Alpha Hunt published a 2025 retrospective arguing that the year's biggest losses came from stolen tokens, OAuth abuse, identity and SaaS attacks, and edge-device weaknesses rather than major zero-day events.

Palo Alto Networks publishes 2025 cloud security report findings

Palo Alto Networks released its State of Cloud Security Report 2025, reporting widespread attacks on AI systems, rising API and IAM weaknesses, and calling for consolidated cloud and SOC operations with agentic security approaches.

Dec 15, 20256mo ago

Security Boulevard advocates agentic AI for non-human identity security

Security Boulevard published an article describing agentic AI as a way to improve management of non-human identities in cloud environments, especially for the travel industry, through automated and context-aware security operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Organizations
12 linked
International Organization for StandardizationOpen Web Application Security ProjectPalo Alto NetworksMITREAnthropicCloud Security AllianceOpenaiMicrosoft CorporationNational Institute of Standards and TechnologyIsacaGoogleEntro Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AI-Driven Risks and Identity Abuse in Modern Enterprise Security | Mallory