March 2026 Summaries
7 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
AWS IAM Roles Anywhere facilitates external workloads accessing AWS through certificate-based credentials, introducing challenges related to identity and access management, such as overly broad trust anchors and missing certificate revocation lists (CRLs), which can result in unintended access and compromised credentials. The system's over-permissive profiles, lack of clear identity attribution, and long-lived certificates can lead to excessive privileges and persistent access from forgotten systems, potentially exposing customer PII data. Veza addresses these issues by providing end-to-end authorization mapping from certificates to roles and permissions across AWS, SaaS, databases, and on-premises systems, ensuring non-human identities are visible like users and groups. It helps discover trust anchors, CRLs, and IAM profiles, answering critical questions about AWS access while providing extensive coverage across services such as S3, EC2, and KMS, with plans to expand further. Veza's integrations offer over 350 pre-configured queries for enhanced visibility and insights into cloud environments.
Mar 27, 2026
378 words in the original blog post.
In 2026, the rise of Shadow AI poses a significant security threat to enterprises, with a majority of AI-related breaches stemming from inadequate access controls. While many organizations plan to deploy agentic AI, few have established robust governance models, leading to a growing issue of unmonitored AI agents operating within cloud platforms like AWS, Azure, or GCP. These agents, often launched without the knowledge of IT or security teams, create vulnerabilities as they autonomously interact with internal resources and external tools, forming an expanding attack surface. Shadow AI can manifest through private Model Context Protocol (MCP) servers, public tool sprawl, and silent permissions, making it challenging for organizations to maintain visibility and control. To combat these risks, solutions like Veza's Access Graph offer tools to unmask and audit AI agents, identify orphaned AI identities, and enforce accountability by mapping agents to human owners. With the prediction that over 50% of enterprise data access will soon be facilitated by autonomous agents, the need for comprehensive visibility, monitoring, and governance of AI activities is imperative to secure sensitive data against unauthorized access.
Mar 21, 2026
1,280 words in the original blog post.
Veza has enhanced its identity risk management capabilities by integrating direct remediation actions into its query experience, allowing teams to address risks such as dormant accounts and orphaned identities directly from query results without switching contexts. This new feature in Veza's Access Intelligence solution streamlines the process by enabling users to disable risky accounts immediately, complete with safety guardrails, a preview of affected accounts, and a mandatory audit trail. The integration aims to reduce remediation lag, audit gaps, human error, and operational burden by unifying risk visibility and remediation into a single workflow. Veza's platform supports this process across identity systems like Okta, Microsoft Entra ID, and Active Directory, providing a compliance-grade audit trail that captures every action taken. This innovation reflects a shift towards making risk visibility and remediation a seamless, continuous motion within the same platform, enhancing efficiency and accountability in identity security management.
Mar 20, 2026
1,349 words in the original blog post.
Stryker, a prominent medical technology company, experienced a severe cyberattack by the pro-Iranian hacker group Handala, which claimed to have erased data from over 200,000 devices and extracted 50 terabytes of sensitive information, causing global disruptions across the company's operations. The hackers exploited Stryker’s administrative access in Microsoft 365, Entra ID, and Intune to conduct remote wipes, highlighting significant vulnerabilities in identity and access management (IAM) practices, particularly regarding overly permissive roles and weak authentication controls. The incident underscores the rising threat of "living-off-the-land" attacks, where attackers leverage existing software tools for malicious purposes. Veza, a security platform, offers a solution by providing visibility into permissions and access paths across cloud environments, enabling organizations to identify and mitigate vulnerabilities before they are exploited. In response to the Stryker breach, Veza developed a specialized dashboard that detects vulnerabilities related to device wipe capabilities, helping security teams prevent unauthorized actions by monitoring and adjusting access privileges. The tool emphasizes the importance of robust multi-factor authentication and the implementation of least-privilege principles to reduce the risk of similar attacks.
Mar 17, 2026
824 words in the original blog post.
Veza's latest release, 2026.2, expands identity governance capabilities to encompass non-human identities, AI agents, and cross-system provisioning, enhancing tools for security engineers, app and data owners, and IT and audit teams. Key updates include improved enterprise integration for systems like Active Directory and Okta, a redesigned interface with streamlined navigation and a unified dashboards experience, and advanced query capabilities in Access Visibility. The release also introduces features such as Slack notifications for Access Reviews, enhanced AI agent security with integration into ServiceNow and Azure AI Foundry, and Lifecycle Management updates, including Predictive Safety Limits and property change detection. These additions aim to provide more reliable, visible, and automated governance, addressing the complexities of modern identity infrastructure and improving the precision and safety of business operations.
Mar 16, 2026
2,739 words in the original blog post.
Non-Human Identities (NHIs), which include service accounts, bots, and API keys, currently surpass human users by 17 to 1 and are responsible for controlling 80% of cloud resources, as reported in the Veza 2026 State of Identity and Access Report. Despite their prevalence, NHIs often lack the security measures applied to human identities, leading to a vast "shadow" attack surface. To secure NHI lifecycles without hindering deployment speed, organizations should establish a single source of truth to manage identities, apply "identity-first" security principles, automate lifecycle management, and monitor behavioral patterns. This involves using automated tools for real-time inventory, assigning ownership, enforcing the Principle of Least Privilege, leveraging short-lived credentials, employing zero trust architecture, centralizing secrets in secure vaults, automating key rotations, ensuring rigorous offboarding, and setting up anomaly detection systems. By decomposing the identity lifecycle into manageable units and automating processes, organizations can effectively reduce operational burdens and enhance security.
Mar 04, 2026
616 words in the original blog post.
ServiceNow has successfully acquired Veza, marking a significant milestone for both companies in the realm of identity security and the modern enterprise. This partnership aims to redefine identity as a control plane essential for the operation and innovation of agentic enterprises, particularly as AI agents become more integrated into workflows. Veza, established in 2020, developed the Access Graph to provide clarity on user permissions, aiding enterprises in eliminating risky or unnecessary access. The collaboration will integrate Veza’s identity control plane with ServiceNow's platform, creating a unified governance system crucial for managing identities across human and AI agents. This integration is timely, as identity and access management spending is projected to grow significantly, highlighting the increasing importance of identity security in digital transformation. The shared vision between ServiceNow and Veza emphasizes rapid iteration and customer feedback to innovate beyond traditional identity management practices, ultimately aiming to offer deeper visibility and governance in the ever-evolving landscape of enterprise security.
Mar 02, 2026
901 words in the original blog post.