Agent Access Tightens, Offense Accelerates, Sovereignty Hardens, and PQC Becomes Procurement Deadline

By DripPublished

The gist

Cyber security is shifting from point products to control planes: agent access, AI-driven attacks, sovereignty, and post-quantum readiness are becoming procurement and governance tests.

This week’s developments

MCP Firewalls and Short-Lived Tokens Tighten Agent Access

Microsoft extended the model into the enterprise stack with Entra Conditional Access and Identity Protection for agent identities plus an MCP Firewall to discover MCP servers, block unauthorized ones, and enforce method-level policy. Rubrik took a more execution-level approach, adding OWASP MCP Top 10-aligned guardrails, federated identity through Okta and Microsoft Entra ID, and short-lived tokens minted per tool call so agent permissions stay aligned with human RBAC. Descope’s Cross-App Access uses the Identity Assertion JWT Authorization Grant so an AI agent can reach another app’s API or MCP server without a second login; Thales’ Consent Management v2 streamlines multi-tenant consent with OAuth2 Bearer JWTs; and Curity is treating AI agents as third-party apps that should receive time-limited, least-privilege consent, ideally per transaction. CAMARA and the CSA are pointing the same way, replacing static keys and repeated logins with centralized, scoped delegation.

The urgency is clear: Hush Security found hardcoded credentials in 12% of credential slots across roughly 82,000 public MCP config files, and GitGuardian reported 24,008 unique secrets in public MCP-related GitHub configs, including 2,117 valid credentials. Identity governance, secret hygiene, and agent authorization are now converging into one control plane, and the next step for practitioners is to extend the continuous controls from last week into delegated access, so non-human identities are governed end to end.

Who will own delegated identity in MCP security?

If you operate in this industry

  • Agent access is becoming an identity-governed control plane, not a sidecar.
  • Expect platform vendors to fold MCP policy, secrets, and delegated auth into core stacks; buy for end-to-end control, not point fixes.

Sources

If you sell into this industry

  • MCP security is shifting from detection to enforced, per-call authorization.
  • Roadmap must prove short-lived tokens, method-level policy, and federated identity; otherwise you look like a scanner, not a control layer.

Sources

If you invest in this industry

  • The winner will own delegated identity, not just secret discovery.
  • Back vendors that can unify IAM, secrets, and agent policy; pure MCP hygiene tools risk being commoditized by platform suites.

Sources

Agentic Offense Compresses the Full Kill Chain

Researchers said the “PaperCut” campaign used hundreds of AI agents to research, weaponize, validate in a private lab, and mass-exploit two chained vulnerabilities, compromising at least 440 instances across 395 organizations in 48 countries. That is a clear step beyond AI as a copilot or lure generator: AI is now being used as the execution fabric for exploitation itself.

The same week brought reports of autonomous intrusions in Spain and Taiwan where AI agents handled reconnaissance, access, post-compromise discovery, and data theft with little or no human intervention. AI is also scaling mobile phishing through multilingual smishing, QR phishing, and mobile-optimized credential harvesters, with employee-device phishing events up 380% since January 2025 and malicious-link clicks up 110% year over year.

The strategic implication is straightforward: manual triage is becoming structurally mismatched to attack tempo. Defensive buying is shifting toward AI-driven SOC, detection, and response platforms that can prove lower analyst load and faster containment, while acquisitions such as Quorum Cyber’s purchase of Ontinue point to rising demand for AI-native operations against machine-speed adversaries.

How do we defend and monetize against machine-speed AI attackers?

If you operate in this industry

  • AI is turning attacks into machine-speed campaigns, not human events.
  • Build or buy AI-native detection and response that cuts analyst load; manual triage is now too slow for autonomous intrusions.

Sources

If you sell into this industry

  • Buyers now want proof your product can fight machine-speed attackers.
  • Shift roadmap to autonomous detection, response, and validation; sell on lower analyst burden and faster containment, not just alerts.

Sources

If you invest in this industry

  • AI defense is moving from nice-to-have to budget-critical infrastructure.
  • Back AI-native SOC and response platforms; point tools and human-heavy services face margin pressure as attack tempo rises.

Sources

Australia’s Cloud Register Draws a Harder Sovereignty Line

Australia’s decision to exclude Google Cloud from the federal whole-of-government cloud register pushed the sovereignty debate from procurement language into an operational control test. The Digital Transformation Agency looked at foreign-law exposure, operational decision-making, and susceptibility to jurisdictional compulsion, even when data is stored locally. Google had already cleared IRAP security review; the blocker was whether its structure fit Canberra’s sovereign-control model. At the time cited, only six vendors were on the register: AWS, Microsoft, IBM, Oracle, SAP, and Rimini Street.

The same logic is spreading into product and personnel risk. The EU’s Cyber Resilience Act adds a 24-hour breach-reporting duty for manufacturers of products with digital elements, including certain wallet products, layering product-level disclosure on top of DORA and NIS2. China is linking export-control compliance to exit bans, raising the stakes for individuals involved in sensitive cross-border transfers in encryption, advanced chips, telecom equipment, and cloud or AI systems.

For operators, vendor qualification now reaches ownership, governance rights, and reporting readiness. For vendors and investors, the value pool is shifting further toward sovereign-ready architectures, local control models, and compliance operations that can absorb rapid disclosure and jurisdictional scrutiny without breaking global delivery economics.

How should vendors adapt to sovereignty as an operational control test?

If you operate in this industry

  • Sovereignty is now an operational control test, not a checkbox.
  • Reassess cloud and security vendors for foreign-law exposure, governance rights, and rapid disclosure readiness before procurement gets blocked.

Sources

If you sell into this industry

  • Sovereign-ready architecture is becoming a deal gate, not a feature.
  • Build local-control, audit, and breach-reporting capabilities into the roadmap; global delivery alone won't clear federal and regulated buyers.

Sources

If you invest in this industry

  • Capital is shifting to vendors that can pass sovereignty and disclosure tests.
  • Favor platforms with local-control models and compliance ops; vendors exposed to foreign jurisdiction or slow reporting face slower adoption.

Sources

PQC Moves From Strategy to Procurement Requirement

PQC is moving from strategy to execution, and from a research agenda to a procurement requirement. Cloudflare is productizing migration at the network edge, Thales is pushing PQC into root-of-trust hardware, and the Pentagon is turning readiness into a dated compliance obligation with inventory, governance, and replacement consequences.

That shift changes buying criteria across cloud, HSM, networking, and security infrastructure. Crypto-agility, migration tooling, and certification evidence are becoming core platform requirements, not optional add-ons. Vendors that can prove upgrade paths and operational readiness will be better positioned as buyers start treating PQC as a budgeted infrastructure cycle rather than a future-proofing exercise.

Where will PQC procurement spending concentrate first?

If you operate in this industry

  • PQC readiness is now a buying criterion, not a roadmap nice-to-have.
  • Prioritize vendors with crypto-agility, migration tooling, and proof of upgrade paths; weak PQC readiness now becomes procurement risk.

Sources

If you sell into this industry

  • PQC is becoming a product requirement buyers will budget for now.
  • Ship migration tooling, certification evidence, and hardware/software upgrade paths fast; PQC readiness will shape win rates in core deals.

Sources

If you invest in this industry

  • PQC turns compliance into spend, favoring platform and infra winners.
  • Expect budget to shift into HSM, cloud, and network vendors with credible migration paths; pure research plays risk getting left behind.

Sources

Stay ahead in Cyber Security

Get the weekly Cyber Security brief in your inbox — the developments, what they mean by vantage, and what to do next.