Cisco joins a growing list of security platform providers that are betting that securing the agentic workforce means turning identity into the primary control plane.

Cisco is enhancing its security offerings by acquiring two companies, Astrix Security and WideField, to bolster its capabilities in securing the agentic workforce. This strategic move signals Cisco's commitment to making identity the central element in its security architecture.
The acquisition of Astrix Security is expected to bring technology that provides visibility and control over non-human identities, such as machine-to-machine connections, APIs, and service accounts. These identities, often referred to as machine identities or non-human identities (NHI), are increasingly crucial for modern applications and infrastructure but can be challenging to manage and secure effectively.
WideField's technology is anticipated to add capabilities related to network security and threat detection. While specific details on WideField's contribution are not provided, its integration likely aims to strengthen Cisco's ability to monitor network activity and identify potential threats.
By integrating these acquisitions, Cisco aims to provide a more comprehensive security solution that addresses the evolving landscape of work, where a significant portion of operations relies on automated processes and interconnected systems. The focus on the "agentic workforce" suggests an emphasis on securing the automated agents and services that perform tasks on behalf of users or systems.
The move aligns with a broader trend in the cybersecurity industry, where companies are increasingly viewing identity as the fundamental control point for security. This approach recognizes that as traditional network perimeters dissolve and more resources move to the cloud, verifying and managing the identity of every user and machine becomes paramount.
Securing non-human identities is a particularly growing concern. These entities often have broad access privileges and can be exploited by attackers to gain a foothold in an organization's network or to disrupt critical operations. Traditional security tools may not be adequately equipped to monitor and govern the behavior of these machine identities.
Cisco's strategy with these acquisitions appears to be centered on building a security platform where identity verification and management are not just a component but the core foundation upon which other security controls are built. This could lead to more granular policy enforcement and improved threat detection by understanding the context of every interaction, whether human or machine.
The integration of Astrix and WideField is expected to enhance Cisco's existing security portfolio, offering customers a more unified approach to managing and securing their digital assets in an increasingly complex environment. The company is positioning itself to address the security challenges posed by the rise of automation and interconnected systems.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a