The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.

Cyera has reportedly acquired Oasis Security in a deal valued at $1 billion, with the strategic intent to integrate artificial intelligence (AI) agent control into its existing data security framework. The acquisition is understood to be driven by a vision to unify data security and identity management within a singular control plane, specifically tailored for AI agents. This move signals a significant shift in how security is approached in an increasingly AI-driven enterprise environment.
The core technical mechanism behind this acquisition appears to be the redefinition of privileged access. Traditionally, privileged access management (PAM) has revolved around static roles and permissions assigned to human users or service accounts. With the integration of Oasis Security's capabilities, Cyera aims to redefine this paradigm, basing privileged access for AI agents on dynamic business context rather rather than fixed roles. This means an AI agent's access to data and systems would be determined by its current operational task and the specific business need it is fulfilling, offering a more granular and adaptive security posture.
The affected product or vendor in this context is Cyera itself, which is expanding its security offerings through this acquisition. Oasis Security's technology will presumably be integrated into Cyera's existing data security platform, enhancing its capabilities to manage and secure interactions involving AI agents. This convergence is particularly relevant for organizations heavily leveraging AI for data processing, analysis, and automation, where the agents themselves become critical entities requiring robust security governance.
The likely scope of this integration extends to any enterprise deploying AI agents that interact with sensitive data. As AI agents become more autonomous and pervasive in business operations, controlling their access and ensuring their actions align with security policies becomes paramount. This class of solution is designed to address the unique security challenges posed by AI, such as ensuring agents do not exfiltrate data, misuse privileges, or operate outside their intended parameters.
Typical mitigation guidance for issues related to AI agent control would involve implementing robust identity and access management (IAM) solutions specifically designed for non-human entities, continuous monitoring of agent activities, and establishing clear audit trails. Furthermore, defining least privilege principles based on dynamic context, as Cyera aims to do, is a critical step in minimizing the attack surface associated with AI agents.
This acquisition reflects a broader industry trend towards securing the evolving landscape of AI-driven operations. As AI agents gain more autonomy and access to critical data and systems, the need for specialized security solutions that can manage their identities, control their access, and monitor their behavior becomes increasingly urgent. The convergence of data security and identity management, particularly with a focus on dynamic, context-aware access for AI agents, represents a significant step in addressing these emerging security challenges in the enterprise.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets