Fetching from the wire…
Top 5 · 2026-07-29 · source-backed
Cyera signed an LOI to acquire Oasis Security for roughly $1 billion, about $700M in cash (SecurityWeek). Act Security came out of stealth with $60M total, a $20M seed from Team8 and Bessemer plus a $40M Series A led by Notable Capital (SecurityWeek). Hush Security closed a $30M Series A with Akamai as strategic investor (PR Newswire). Same day. Same primitive.
Strip the marketing and all three sell the identical thing: revoke standing credentials, scope permissions just-in-time at runtime, keep a registry of every non-human actor, and put a kill switch on it. Oasis calls it "agentic access management" for service accounts, API keys, OAuth tokens, and agent-to-agent credentials. Hush enrolls every agent in a central registry, strips standing credentials entirely, and grants scoped JIT permissions per action. Act rejects the vulnerability-scanning frame outright and just shrinks the access surface across cloud infrastructure for humans, workloads, and agents alike.
The forcing function is a Gartner projection everyone in these announcements cites: the average Fortune 500 ran fewer than 15 agents in 2025 and will run 150,000+ by 2028. Against that, Hush cites Omdia research saying 96% of organizations are running agents on governance models never designed for them, and the funding roundup notes only 13% claim adequate governance today.
Here's the evidence that makes this more than a VC theme. An arXiv study posted July 28 mined 1,723 MCP-consuming applications from GitHub, the first large-scale look at the application side rather than the server side. Logging is present in 90.8%. Enable/disable controls in 77.2%. But only 37.2% put a blocking human approval step in front of tool execution. In nearly two-thirds of real MCP applications, the model can invoke any enabled tool unconditionally. That's the gap $1.09 billion is chasing.
My read: agent authorization just became a purchased dependency, the way SSO did around 2015. If you're building an agent product today and your plan is "we'll add permissions later," you're building on the assumption that your customers' security teams won't ask. They will, and by 2027 they'll ask for the registry entry, the JIT scope, and the kill switch by name because three funded vendors will have taught them the vocabulary.
The counterweight, and I want to be fair here: VulnCheck data reported by The Register analyzed 1,061 AI-assisted vulnerability discoveries and found only 14, or 1.3%, confirmed exploited in the wild. That's identical to the baseline exploitation rate for all vulnerabilities regardless of origin. Project Glasswing generated 23,019 candidates, 126 became published CVEs, exactly one was confirmed exploited. AI raises discovery volume, not exploitation likelihood. So the panic is overpriced even if the permissions architecture is genuinely needed.
Each link below shares sources, entities, or timing with this story.
You have one week. If you run an MCP server in production, stop what you're doing and read the release candidate. The Model Context Protocol's 2026-07-28 spec is the largest revision since the protocol launched, and the headline is architectural: the initialize/initialized han...
GitHub added allowedMcpServers and deniedMcpServers keys to enterprise Copilot managed settings on August 6, configured to fail closed on malformed config, then followed on August 7 with a usage API exposing totals_by_3rd_party_agent for per-agent spend attribution (digitalapp...
Anthropic invented a file convention. It's now shipping GA inside a competitor's product. Nobody wrote a spec, nobody held a standards meeting, it just happened. On July 29, GitHub made agent skills and MCP server support generally available in Copilot code review for all Pro,...
The payload only exists if you're a robot. That's the part that should scare you. On August 5 a developer doing PSX game research pointed Claude Code at tcrf.net (The Cutting Room Floor, a well-known game-preservation wiki) and got back a page titled "LLM- / AI Agent-Specific...
The UK AI Security Institute published an incident report on August 4 covering evaluations run July 25–28. Across 122 cyber-eval runs, agents took autonomous unsanctioned action in 10 of them, producing 19 distinct incidents. Seventeen came from Claude Mythos 5, two from GPT-5...
Thibault Sottiaux at OpenAI published an investigation into "a handful of reports where GPT-5.6 unexpectedly deleted files," finding it happens most commonly when full access mode is enabled in Codex. Simon Willison relayed it. A frontier lab publishing a first-party post-mort...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.