<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Access Control</title><description>Cybersecurity articles tagged #Access Control on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cyera Acquires Oasis Security for AI Agent Control</title><link>https://runtimerebel.com/blog/cyera-acquires-oasis-security-for-ai-agent-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyera-acquires-oasis-security-for-ai-agent-control</guid><description>Cyera&apos;s $1 billion acquisition of Oasis Security aims to unify data security and identity management for AI agents, redefining access control.</description><pubDate>Fri, 14 Aug 2026 16:43:25 GMT</pubDate><category>AI Agents</category><category>Identity Management</category><category>Data Security</category><category>Access Control</category><category>Cyera</category></item><item><title>NodeBB 4.14.2 Release Patches Eight AI-Discovered Vulnerabilities</title><link>https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/nodebb-4-14-2-release-patches-eight-ai-discovered-vulnerabilities</guid><description>NodeBB patches eight high-severity vulnerabilities discovered by AI, preventing unauthorized admin access and private chat exposure in versions before 4.14.0.</description><pubDate>Fri, 24 Jul 2026 10:19:56 GMT</pubDate><category>Nodebb</category><category>AI Security</category><category>Aikido Security</category><category>Web Security</category><category>Access Control</category></item><item><title>RabbitMQ Flaws: OAuth Secret Leak &amp; Cross-Tenant Data Exposure</title><link>https://runtimerebel.com/blog/rabbitmq-flaws-oauth-secret-leak-cross-tenant-data-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/rabbitmq-flaws-oauth-secret-leak-cross-tenant-data-exposure</guid><description>Two RabbitMQ access control flaws enable OAuth secret leakage, cross-tenant data exposure, and potential messaging infrastructure takeover risks.</description><pubDate>Tue, 14 Jul 2026 17:20:57 GMT</pubDate><category>RabbitMQ</category><category>OAuth</category><category>Access Control</category><category>Message Broker</category><category>Data Leak</category><category>Security Flaw</category><category>Cross Tenant</category></item><item><title>Microsoft Teams: New Controls for AI Bot Meeting Access</title><link>https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</guid><description>Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.</description><pubDate>Thu, 02 Jul 2026 07:37:17 GMT</pubDate><category>Microsoft Teams</category><category>AI Bots</category><category>Meeting Security</category><category>Access Control</category><category>Cloud Security</category></item><item><title>AI Agents: The Emerging Identity &amp; Governance Challenge</title><link>https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</guid><description>Unmanaged AI agents pose significant security risks by operating as uncontrolled identities with access to sensitive enterprise systems. Learn mitigation strategies.</description><pubDate>Fri, 19 Jun 2026 16:54:42 GMT</pubDate><category>AI Security</category><category>AI Agents</category><category>Identity Management</category><category>Access Control</category><category>Governance</category><category>Token Security</category></item><item><title>Orphaned AI Agents: Mitigating Hidden Access Risks in Enterprise AI</title><link>https://runtimerebel.com/blog/orphaned-ai-agents-mitigating-hidden-access-risks-in-enterprise-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/orphaned-ai-agents-mitigating-hidden-access-risks-in-enterprise-ai</guid><description>Learn about the hidden access risks posed by orphaned AI agents and standing privileges in enterprise networks. Discover strategies to secure AI deployments.</description><pubDate>Thu, 18 Jun 2026 13:21:10 GMT</pubDate><category>AI Security</category><category>Orphaned AI Agents</category><category>Access Control</category><category>Privilege Management</category><category>Enterprise AI</category><category>Shadow IT</category></item><item><title>Securing Advanced AI Models: Addressing Dual-Use Risks</title><link>https://runtimerebel.com/blog/securing-advanced-ai-models-addressing-dual-use-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-advanced-ai-models-addressing-dual-use-risks</guid><description>Industry professionals discuss critical aspects of AI model security, focusing on dual-use capabilities, robust safeguards, and effective tiered access mechanisms.</description><pubDate>Fri, 12 Jun 2026 13:20:59 GMT</pubDate><category>AI Security</category><category>Large Language Models</category><category>Dual Use Technology</category><category>Responsible AI</category><category>Access Control</category><category>AI Governance</category></item><item><title>CVE-2024-40766: Patch SonicWall SonicOS Improper Access Control</title><link>https://runtimerebel.com/blog/cve-2024-40766-patch-sonicwall-sonicos-improper-access-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-40766-patch-sonicwall-sonicos-improper-access-control</guid><description>SonicWall urges immediate patching of CVE-2024-40766, a critical access control flaw in SonicOS affecting Gen 5, 6, and 7 firewalls.</description><pubDate>Thu, 30 Apr 2026 16:38:18 GMT</pubDate><category>CVE-2024-40766</category><category>SonicWall</category><category>SonicOS</category><category>Firewall</category><category>Access Control</category></item><item><title>Zero Trust Implementation Stalled by Secure Data Movement Bottlenecks</title><link>https://runtimerebel.com/blog/zero-trust-implementation-stalled-by-secure-data-movement-bottlenecks</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-implementation-stalled-by-secure-data-movement-bottlenecks</guid><description>New Cyber360 research reveals why organizations fail to achieve Zero Trust by prioritizing network connectivity over granular data movement security.</description><pubDate>Tue, 28 Apr 2026 16:41:38 GMT</pubDate><category>Zero Trust</category><category>Data Security</category><category>Cyber360 Report</category><category>Network Architecture</category><category>Access Control</category></item><item><title>CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis</title><link>https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</guid><description>CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender&apos;s access control mechanisms. Learn how to secure your systems.</description><pubDate>Thu, 23 Apr 2026 05:05:39 GMT</pubDate><category>CVE-2026-33825</category><category>Microsoft Defender</category><category>CISA KEV</category><category>Access Control</category><category>Windows Security</category></item><item><title>Ivanti Neurons for ITSM Patches CVE-2024-45504 and CVE-2024-45505</title><link>https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505</guid><description>Ivanti addresses two high-severity flaws in Neurons for ITSM, CVE-2024-45504 and CVE-2024-45505, preventing session persistence and cross-user data exposure.</description><pubDate>Wed, 15 Apr 2026 12:31:03 GMT</pubDate><category>Ivanti</category><category>ITSM</category><category>CVE-2024-45504</category><category>CVE-2024-45505</category><category>Authentication Bypass</category><category>Access Control</category></item><item><title>CVE-2026-35616: Fortinet FortiClient EMS Vulnerability — KEV Alert</title><link>https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-fortinet-forticlient-ems-vulnerability-kev-alert</guid><description>CISA adds CVE-2026-35616 affecting Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalog. Learn how to mitigate this access control flaw.</description><pubDate>Mon, 06 Apr 2026 16:23:16 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>KEV</category><category>Access Control</category></item><item><title>Drift Protocol Compromise: Admin Control Seized, $280M Lost</title><link>https://runtimerebel.com/blog/drift-protocol-compromise-admin-control-seized-280m-lost</link><guid isPermaLink="true">https://runtimerebel.com/blog/drift-protocol-compromise-admin-control-seized-280m-lost</guid><description>Analysis of the Drift Protocol incident where a threat actor seized Security Council powers, leading to a $280 million loss. Learn about the attack vector and mitigation.</description><pubDate>Thu, 02 Apr 2026 20:15:38 GMT</pubDate><category>Drift Protocol</category><category>Cryptocurrency</category><category>DeFi</category><category>Administrative Control</category><category>Security Council</category><category>Financial Loss</category><category>Access Control</category></item><item><title>LLMs &amp; Access Control: Mitigating Policy Drift and Authorization Risks</title><link>https://runtimerebel.com/blog/llms-access-control-mitigating-policy-drift-and-authorization-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llms-access-control-mitigating-policy-drift-and-authorization-risks</guid><description>LLMs can silently degrade access control policies in Rego and Cedar, leading to authorization risks and least-privilege model erosion.</description><pubDate>Mon, 30 Mar 2026 16:29:15 GMT</pubDate><category>LLM</category><category>Access Control</category><category>Authorization</category><category>Policy Drift</category><category>Rego</category><category>Cedar</category><category>Least Privilege</category><category>AI Security</category></item><item><title>Gambit Security Raises $61M to Converge Physical and Cyber Security</title><link>https://runtimerebel.com/blog/gambit-security-raises-61m-to-converge-physical-and-cyber-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/gambit-security-raises-61m-to-converge-physical-and-cyber-security</guid><description>Gambit Security exits stealth with $61M in funding to integrate physical access control and video surveillance into modern enterprise IT security stacks.</description><pubDate>Thu, 26 Feb 2026 16:27:59 GMT</pubDate><category>Gambit Security</category><category>Physical Identity and Access Management</category><category>Access Control</category><category>SaaS</category><category>Cyber Physical Convergence</category><category>PIAM</category></item></channel></rss>