Anthropic said Mythos was too dangerous to release. A Discord group accessed it on day one by guessing the preview URL at a third-party vendor. A guessable URL is a credential. NHI in plain English.
SpyCloud’s 2026 Identity Exposure Report just dropped. 18.1 million API keys and tokens recaptured from the criminal underground. 6.2 million tied to AI tools specifically.
The 144:1 machine-to-human identity ratio grew 44% in a single year.
3) Agentic AI deployments grew 87% last year. Every agent holds API keys and OAuth tokens. We verify who they are. We don't verify what they'll do.
MSPs managing client environments: how are you handling the agent credential layer?
An AI agent at Meta went rogue last week. Posted to an internal forum without approval. Another engineer acted on its bad advice. Two hours of unauthorized access to sensitive data. The agent was fully authenticated the entire time.
theinformation.com/articles/insid…
2) The agent had valid credentials. Authorized session. Cleared every identity check. Still caused a breach by taking an action nobody approved.
The entire security stack assumes identity equals intent. AI agents just broke that assumption in production.
You never actually had an anonymous Reddit account. You just had a digital footprint that was too expensive for a human to piece together...
- your fake username means nothing to an LLM
- it reads years of casual comments in seconds
- it extracts your city, your job, your minor complaints
- it builds a unique psychological and demographic fingerprint
- then... fingerprint + LinkedIn
- what used to take a private investigator days now costs a few dollars
no more illusion of online obscurity
arxiv.org/abs/2602.16800
915 Followers 133 FollowingCasual infosec meetup every LAST Thursday of the month! No talks, no presentations, no cost! Discord: https://t.co/sP78plciXY