cd /news/ai-safety/ai-agent-security-cyeras-1b-oasis-ac… · home topics ai-safety article
[ARTICLE · art-78165] src=byteiota.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

AI Agent Security: Cyera’s $1B Oasis Acquisition

Data security company Cyera agreed to acquire non-human identity startup Oasis Security for approximately $1 billion, a deal that underscores the industry's recognition that AI agents are running in production with unmanaged credentials and permissions. The average enterprise now maintains 45 non-human identities for every human employee, and 92% of organizations report their legacy IAM tools cannot manage AI agent identity risks, according to Security Boulevard research.

read4 min views5 publishedJul 29, 2026
AI Agent Security: Cyera’s $1B Oasis Acquisition
Image: Byteiota (auto-discovered)

Yesterday, data security company Cyera agreed to acquire non-human identity startup Oasis Security for approximately $1 billion. The deal, announced July 28, 2026 on TechCrunch, is less about two companies merging and more about an industry admitting out loud what practitioners have known for months: AI agents are running in production with credentials nobody is tracking, permissions nobody audited, and access nobody can revoke fast enough when things go wrong.

Your Agents Already Outnumber Your Employees 45 to 1 #

The average enterprise now maintains 45 non-human identities — service accounts, API keys, machine credentials, agent tokens — for every human employee. For a 1,000-person organization, that’s roughly 45,000 machine identities today and a projected 93,000 within two years. In Fortune 500 companies, non-human identity counts grew 500% in the past six months alone.

The deployment-to-security ratio is more revealing than any headline number. According to Security Boulevard’s NHI research, agent framework packages — LangChain, CrewAI, the OpenAI Agents SDK — received 483 million downloads in May 2026 alone. Security and guardrail packages received 5.8 million. That 83:1 gap widened 41% between January and May. Developers are shipping agents as fast as frameworks allow; security is trailing by design.

Meanwhile, 92% of organizations report their legacy IAM tools cannot manage AI agent identity risks. Most track credentials on spreadsheets. Only 12% have automated lifecycle management. The remaining 88% are manually tracking identities that operate at machine speed.

Why AI Agents Are More Dangerous Than Old Service Accounts #

The mental model most developers use for AI agents — “it’s basically a service account” — is wrong in a way that matters. A traditional service account sits in one system, holds one credential, and does one job. An AI agent acquires permissions dynamically at runtime, spawns sub-agents, invokes external APIs, writes and executes code, and chains actions across dozens of systems in a single task. Compromise one agent token and the blast radius is exponentially larger than a stolen service account password.

The Salesloft-Drift breach from August 2025 illustrated exactly this. Threat actor UNC6395 stole OAuth tokens from a single integration and targeted Salesforce instances at more than 700 organizations — no malware required, just token abuse at machine velocity. The timing problem compounds the exposure: attackers exploit exposed AWS credentials within 17 minutes on average, while a quarter of organizations take more than 24 hours to rotate compromised credentials. That is an 85x speed advantage for the attacker.

Related:[T3MP3ST: Your AI Coding Agent Is Now a Red-Team Operator]

The MCP Authentication Problem Is Already Here #

MCP — the protocol now standard for connecting AI agents to external tools — has a serious authentication gap in production. Analysis of 7,973 live MCP servers found that 40% had zero authentication enabled. Every OAuth-enabled MCP server tested (119 servers) carried at least one authentication vulnerability; specifically, 96.6% were affected by dynamic client registration flaws that allow unauthorized clients to impersonate legitimate agents. GitGuardian found roughly 24,000 secrets sitting in MCP configuration files on public GitHub.

AI-assisted development has made the secrets problem worse, not better. GitGuardian’s State of Secrets Sprawl 2026 found 28.65 million new hardcoded secrets added to public GitHub commits in 2025 — a 34% year-over-year increase. AI service secrets surged 81%. AI-assisted commits leak secrets at double the base rate of human-written code. The tooling that helps developers move faster is generating credentials that nobody is rotating.

What Cyera and Oasis Build Together #

Oasis Security’s platform inventories and monitors non-human identities across cloud, SaaS, on-premises systems, and AI agents and MCP servers. It discovers dormant accounts, flags excessive permissions, detects credential anomalies through its Oasis Scout behavioral engine, and automates lifecycle management including rotation. The integration with Azure, AWS, GCP, and Zscaler means coverage across the environments where most enterprise agents actually run.

Cyera brings data discovery and classification to the combination. Together, the platform answers both critical questions: what sensitive data does your organization hold, and which humans, machines, and AI agents can touch it. Cyera CEO Yotam Segev framed it directly: “Knowing your data isn’t enough if you can’t govern who or what touches it.” This is Cyera’s third acquisition in 2026. Expect CrowdStrike, Palo Alto, and Wiz to make similar moves before year end.

Key Takeaways #

  • Non-human identities now outnumber human users 45:1 in the average enterprise, and 92% of legacy IAM tools cannot manage AI agent credentials
  • AI agents are not service accounts — dynamic permissions and multi-system chaining make compromised agent tokens far more dangerous, and attackers exploit them 85x faster than most teams can rotate
  • 40% of live MCP servers have zero authentication, and AI-assisted code doubles the rate of hardcoded secret leakage in public repositories
  • The Cyera-Oasis deal signals that non-human identity management is becoming standard enterprise infrastructure — build your plan before your security team mandates one
  • Start now: assign individual identities per agent, use short-lived tokens, audit MCP server authentication, and assume credentials are already compromised until proven otherwise
── more in #ai-safety 4 stories · sorted by recency
── more on @cyera 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-agent-security-cy…] indexed:0 read:4min 2026-07-29 ·