Token Security Warns SOC 2 Controls May Fail to Distinguish AI Agent Activity from Human Actions
Analysis highlights compliance gaps as AI agents increasingly operate using human credentials across cloud environments.

Key Takeaways
- AI agents operating through human credentials may evade SOC 2 access governance and anomaly detection.
- The advisory identifies a compliance gap, not an active exploitation event.
- Token Security recommends agent identity governance and behavior-based anomaly detection as mitigations.
- No standardized SOC 2 framework updates addressing AI agent identities are currently available.
Related Security News

JadePuffer Agentic AI Attacks Target Azure Tenants, Destroy Cloud Resources
Security researchers have observed the JadePuffer ransomware operator conducting agent-driven attacks against Azure cloud tenants. The attacks involve reconnaissance, credential theft, and the destruction of core cloud components. Details regarding the specific use of agentic AI remain reported but unconfirmed.

Carbonato Botnet Leverages Hermes Agent AI Framework to Compromise Docker Hosts
Security researchers have identified a new botnet campaign, tracked as Carbonato, that repurposes the open-source Hermes Agent AI framework to compromise Docker hosts. The malware leverages exposed container endpoints to execute arbitrary commands through Telegram integration and harvests AI API keys and other sensitive credentials stored on compromised systems.



_Dzmitry_Skazau_Alamy.jpg?width=720&quality=80&disable=upscale)