Skip to main content

Host Access News - September 2026

  • September 29, 2026
  • 0 replies
  • 4 views

Evan Tackett

Identity Is Still the Fastest Path In

For years, security professionals have focused on strengthening authentication. But recent events remind us that attackers are increasingly targeting what happens after authentication rather than trying to break it.

This month's stories highlight a growing reality: organizations must manage and monitor every identity, every session, and every privilege, whether the user is human, machine, or AI-powered.

MFA Isn't the Finish Line

A recently uncovered phishing-as-a-service operation known as BigBear 2.0 compromised more than 3,300 Microsoft 365 users across 461 organizations by stealing authenticated session cookies rather than bypassing authentication itself. Researchers found that attackers could capture valid sessions after users successfully completed MFA and then replay those sessions to gain access to email, collaboration tools, and cloud resources.

The incident reinforces an important lesson: MFA remains essential, but organizations also need visibility into session activity, phishing-resistant authentication, conditional access controls, and continuous monitoring of privileged access.

Takeaway: Security doesn't stop when a user logs in. Monitoring active sessions and access behavior is becoming just as important as verifying identity in the first place.

The Growing Challenge of Non-Human Identities

Service accounts, API keys, automated workloads, bots, and AI agents now vastly outnumber human users in many environments. Yet many organizations continue to manage these identities using processes originally designed for employees.

Industry research continues to show gaps in ownership, governance, lifecycle management, and visibility for non-human identities. These accounts often hold elevated privileges and can persist for years without review, making them attractive targets for attackers.

Takeaway: Identity governance programs can no longer focus exclusively on workforce users. Every credential with access to business systems should be discoverable, governed, and regularly reviewed.

AI Agents Need Identity Governance Too

As organizations deploy more AI-powered assistants and autonomous agents, security teams are discovering a familiar challenge: every AI agent is effectively another identity that needs access controls, ownership, and oversight.

New IDC research sponsored by GuidePoint Security found broad agreement among security leaders that identity serves as the foundational control plane for securing agentic AI. The research also found that organizations are often deploying AI agents faster than they can inventory and govern them. 

The study highlights several priorities:

  • Continuous identity discovery
  • Clear ownership of AI agents
  • Governance and lifecycle management
  • Just-in-time and least-privilege access
  • Identity threat detection and response capabilities

Takeaway: Whether an identity belongs to an employee, a service account, or an AI agent, the same question applies: Who owns it, what can it access, and is that access still appropriate?

The Common Theme: Visibility Matters

From MFA-resistant phishing campaigns to the rapid growth of AI and machine identities, September's stories all point to the same challenge: organizations cannot secure identities they cannot see.

Maintaining visibility into users, service accounts, AI agents, and their access rights is becoming a foundational security requirement. The more connected and automated our environments become, the more important it is to understand who has access to critical systems and how those privileges are being used.

For organizations running host and mainframe applications alongside modern cloud environments, that visibility must extend across the entire enterprise, not just the newest platforms.

Learn More

Want to stay current on identity security trends and discuss best practices with other Rocket customers? Visit the Host Access Community Forum and join the conversation.