Fetching from the wire…
Top 5 · 2026-07-29 · source-backed
Cyera signed an LOI to acquire Oasis Security for roughly $1 billion, about $700M in cash (SecurityWeek). Act Security came out of stealth with $60M total, a $20M seed from Team8 and Bessemer plus a $40M Series A led by Notable Capital (SecurityWeek). Hush Security closed a $30M Series A with Akamai as strategic investor (PR Newswire). Same day. Same primitive.
Strip the marketing and all three sell the identical thing: revoke standing credentials, scope permissions just-in-time at runtime, keep a registry of every non-human actor, and put a kill switch on it. Oasis calls it "agentic access management" for service accounts, API keys, OAuth tokens, and agent-to-agent credentials. Hush enrolls every agent in a central registry, strips standing credentials entirely, and grants scoped JIT permissions per action. Act rejects the vulnerability-scanning frame outright and just shrinks the access surface across cloud infrastructure for humans, workloads, and agents alike.
The forcing function is a Gartner projection everyone in these announcements cites: the average Fortune 500 ran fewer than 15 agents in 2025 and will run 150,000+ by 2028. Against that, Hush cites Omdia research saying 96% of organizations are running agents on governance models never designed for them, and the funding roundup notes only 13% claim adequate governance today.
Here's the evidence that makes this more than a VC theme. An arXiv study posted July 28 mined 1,723 MCP-consuming applications from GitHub, the first large-scale look at the application side rather than the server side. Logging is present in 90.8%. Enable/disable controls in 77.2%. But only 37.2% put a blocking human approval step in front of tool execution. In nearly two-thirds of real MCP applications, the model can invoke any enabled tool unconditionally. That's the gap $1.09 billion is chasing.
My read: agent authorization just became a purchased dependency, the way SSO did around 2015. If you're building an agent product today and your plan is "we'll add permissions later," you're building on the assumption that your customers' security teams won't ask. They will, and by 2027 they'll ask for the registry entry, the JIT scope, and the kill switch by name because three funded vendors will have taught them the vocabulary.
The counterweight, and I want to be fair here: VulnCheck data reported by The Register analyzed 1,061 AI-assisted vulnerability discoveries and found only 14, or 1.3%, confirmed exploited in the wild. That's identical to the baseline exploitation rate for all vulnerabilities regardless of origin. Project Glasswing generated 23,019 candidates, 126 became published CVEs, exactly one was confirmed exploited. AI raises discovery volume, not exploitation likelihood. So the panic is overpriced even if the permissions architecture is genuinely needed.
Each link below shares sources, entities, or timing with this story.
MCP deprecates Logging / Shared entities / Earlier coverage
Linked by a graph relationship (MCP deprecates Logging); both cover Fortune, July, Logging, MCP; earlier Fortune coverage from 2026-07-21.
MCP deprecates Logging / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (MCP deprecates Logging); both cover GitHub, MCP, Same; reported by the same outlet (arxiv.org).
MCP deprecates Logging / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP deprecates Logging); both cover GitHub, MCP, OAuth; overlapping topics (agent, security).
MCP deprecates Logging / Shared entities / Earlier coverage
Linked by a graph relationship (MCP deprecates Logging); both cover July, Logging, MCP, OAuth; earlier July coverage from 2026-07-28.
MCP deprecates Logging / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP deprecates Logging); both cover July, MCP; reported by the same outlet (arxiv.org).
MCP deprecates Logging / Shared entities / Earlier coverage
Linked by a graph relationship (MCP deprecates Logging); both cover Gartner, GitHub, MCP, OAuth; earlier Gartner coverage from 2026-03-07.
Linked by a graph relationship (MCP deprecates Logging); both cover GitHub, July, MCP, Same; earlier GitHub coverage from 2026-07-23.
Claude Code uses OAuth / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Claude Code uses OAuth); both cover Fortune, July, Same; reported by the same outlet (arxiv.org).