AI Security Pulse

Non-Human Identity and Supply Chain Risks

Non-Human Identity and Supply Chain Risks

Credential leaks, long-lived mesh tokens, and ungoverned AI exposure drive market consolidation (Cyera/Oasis, Okta/Permiso). Claude Code's .claude/settings.local.json leak and Hugging Face breach postmortem highlight need for identity gateways and least agency. Attackers now poison open-source AI libraries with AI-generated code, expanding supply chain attack surface.

Sources (2)
Updated Aug 3, 2026