Teleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure.

Teleport has announced a significant expansion of its Identity Security platform, introducing three new features designed to manage and secure the behavior of autonomous AI agents within production infrastructure. These additions, Beams Session Summaries, Agentic Classifiers, and Risk Scoring, aim to establish a framework for identifying and preventing agent misalignment.
The new capabilities are integrated with Beams, Teleport’s trusted runtime environment for agents. The company recently published a white paper, "From Zero Trust to Agent Trust," which argues that traditional zero trust principles, while necessary, are insufficient for governing agents operating at scale. This paper extends zero trust into three agent trust principles: "Verify explicitly" becomes "Enforce continuously," emphasizing a unique, attestable identity and operation within a trusted runtime; "Use least privileged access" evolves into "Bound collective autonomy," addressing the potential for individually authorized actions by a swarm of agents to become collectively destructive; and "Assume breach" transforms into "Assume misalignment," advocating for continuous monitoring and real-time intervention to detect and respond to agent drift.
Beams Session Summaries provide a concise, human-readable overview of an AI agent's actions, including its identity, privileges, tool and API calls, and LLM prompts and responses. This summary also includes the agent's reasoning, establishing a behavioral baseline against its declared objective.
Agentic Classifiers enable the creation of policies that evaluate the behavior of individual agents or groups of agents against company-specific criteria. This allows for the flagging of agent actions that deviate from their stated objectives.
Risk Scoring automatically summarizes SSH, Kubernetes, and database sessions, categorizing them by risk level and mapping actions to the MITRE ATT&CK framework. This feature allows infrastructure and security teams to automate or manually search across sessions for specific commands, resources, or behaviors.
According to Teleport, these new capabilities, in conjunction with Beams, lay the foundation for agent trust by providing agents with a cryptographic, continuously monitored identity. They also make individual and collective risk visible before actions are taken and equip enterprises with tools to detect and respond to misalignment in real time, operationalizing the "assume misalignment" principle. The company states that these features provide an operational harness to observe agent actions, classify expected behavior, and assess the risk of future actions.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs



Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as