<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Cloud Chronicles</title>
    <link>https://permiso.io/blog</link>
    <description>Latest research, product updates and best practices on staying secure in the cloud | Permiso</description>
    <language>en</language>
    <pubDate>Thu, 02 Apr 2026 12:53:44 GMT</pubDate>
    <dc:date>2026-04-02T12:53:44Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Introducing SandyClaw - The First Dynamic Sandbox for AI Agent Skills and Prompts</title>
      <link>https://permiso.io/blog/introducing-sandyclaw-dynamic-sandbox-ai-agent-skills</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/introducing-sandyclaw-dynamic-sandbox-ai-agent-skills" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/SandyClaw%20Sandbox.png" alt="Introducing SandyClaw - The First Dynamic Sandbox for AI Agent Skills and Prompts" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;TL;DR&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;span&gt;AI agent skill marketplaces are the new software supply chain, and attackers are already exploiting them.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;The current generation of skill scanners relies on static code checks or LLM-based evaluation. Neither executes the skill, which means neither detects malicious behavior that only reveals itself at runtime.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;SandyClaw is the first platform to apply dynamic sandbox detonation to AI agent skills.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;It runs the skill in a controlled environment, records every action at the LLM and OS level, and delivers a verdict backed by behavioral evidence rather than inference.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;Available now at &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="http://sandyclaw.permiso.io" style="color: #0600ff;"&gt;sandyclaw.permiso.io&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;The supply chain nobody is securing&lt;/h2&gt; 
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/ai-security" style="color: #0600ff;"&gt;AI agents&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; need skills to do useful work. Skills are downloadable capability packages that teach agents how to interact with tools, APIs, and services. They are distributed through open marketplaces, installed with a single command, and executed with whatever permissions the agent's identity already has.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/introducing-sandyclaw-dynamic-sandbox-ai-agent-skills" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/SandyClaw%20Sandbox.png" alt="Introducing SandyClaw - The First Dynamic Sandbox for AI Agent Skills and Prompts" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;TL;DR&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;span&gt;AI agent skill marketplaces are the new software supply chain, and attackers are already exploiting them.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;The current generation of skill scanners relies on static code checks or LLM-based evaluation. Neither executes the skill, which means neither detects malicious behavior that only reveals itself at runtime.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;SandyClaw is the first platform to apply dynamic sandbox detonation to AI agent skills.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;It runs the skill in a controlled environment, records every action at the LLM and OS level, and delivers a verdict backed by behavioral evidence rather than inference.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;Available now at &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="http://sandyclaw.permiso.io" style="color: #0600ff;"&gt;sandyclaw.permiso.io&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;The supply chain nobody is securing&lt;/h2&gt; 
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/ai-security" style="color: #0600ff;"&gt;AI agents&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; need skills to do useful work. Skills are downloadable capability packages that teach agents how to interact with tools, APIs, and services. They are distributed through open marketplaces, installed with a single command, and executed with whatever permissions the agent's identity already has.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fintroducing-sandyclaw-dynamic-sandbox-ai-agent-skills&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Product</category>
      <category>Featured</category>
      <pubDate>Thu, 02 Apr 2026 12:47:41 GMT</pubDate>
      <guid>https://permiso.io/blog/introducing-sandyclaw-dynamic-sandbox-ai-agent-skills</guid>
      <dc:date>2026-04-02T12:47:41Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
    <item>
      <title>Permiso Security Wins 2026 SC Award for Best Threat Detection Technology</title>
      <link>https://permiso.io/blog/permiso-wins-2026-sc-award-best-threat-detection-technology</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-wins-2026-sc-award-best-threat-detection-technology" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/PR.png" alt="Permiso Security Wins 2026 SC Award for Best Threat Detection Technology" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="line-height: 1.2; text-align: center; font-size: 16px;"&gt;&lt;em&gt;Permiso Security has won the 2026 SC Award for Best Threat Detection Technology, announced on March 24 during&lt;br&gt;RSAC 2026 in San Francisco.&lt;/em&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.2;"&gt;&lt;span&gt;This marks the second consecutive year Permiso has been recognized at the SC Awards. In 2025, the company won &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://www.scworld.com/news/sc-awards-winner-2025-permiso-security-most-promising-early-stage-startup" style="color: #0600ff;"&gt;Most Promising Early-Stage Startup. &lt;/a&gt;&lt;/span&gt;&lt;/span&gt;This year, the recognition moved from the company's promise to its product: the identity security platform that detects and responds to threats across human, non-human, and AI identities in cloud, SaaS, CI/CD, and on-premises environments.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-wins-2026-sc-award-best-threat-detection-technology" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/PR.png" alt="Permiso Security Wins 2026 SC Award for Best Threat Detection Technology" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="line-height: 1.2; text-align: center; font-size: 16px;"&gt;&lt;em&gt;Permiso Security has won the 2026 SC Award for Best Threat Detection Technology, announced on March 24 during&lt;br&gt;RSAC 2026 in San Francisco.&lt;/em&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.2;"&gt;&lt;span&gt;This marks the second consecutive year Permiso has been recognized at the SC Awards. In 2025, the company won &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://www.scworld.com/news/sc-awards-winner-2025-permiso-security-most-promising-early-stage-startup" style="color: #0600ff;"&gt;Most Promising Early-Stage Startup. &lt;/a&gt;&lt;/span&gt;&lt;/span&gt;This year, the recognition moved from the company's promise to its product: the identity security platform that detects and responds to threats across human, non-human, and AI identities in cloud, SaaS, CI/CD, and on-premises environments.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fpermiso-wins-2026-sc-award-best-threat-detection-technology&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <pubDate>Wed, 25 Mar 2026 13:27:10 GMT</pubDate>
      <guid>https://permiso.io/blog/permiso-wins-2026-sc-award-best-threat-detection-technology</guid>
      <dc:date>2026-03-25T13:27:10Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
    <item>
      <title>CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries</title>
      <link>https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/image%20(7)-1.png" alt="CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;AI assistants have genuinely improved day-to-day operations for teams buried in inbox triage, client support, customer success, sales follow-ups, incident response, and everything in between. Microsoft Copilot sits right in the flow: it can summarize emails and meetings, and in some experiences it can also pull context from other Microsoft 365 sources.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/image%20(7)-1.png" alt="CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;AI assistants have genuinely improved day-to-day operations for teams buried in inbox triage, client support, customer success, sales follow-ups, incident response, and everything in between. Microsoft Copilot sits right in the flow: it can summarize emails and meetings, and in some experiences it can also pull context from other Microsoft 365 sources.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fcopilot-prompt-injection-ai-email-phishing&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Research</category>
      <category>Featured</category>
      <pubDate>Thu, 12 Mar 2026 13:00:33 GMT</pubDate>
      <author>andi.ahmeti@permiso.io (Andi Ahmeti)</author>
      <guid>https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing</guid>
      <dc:date>2026-03-12T13:00:33Z</dc:date>
    </item>
    <item>
      <title>Permiso Expands AI Agent Security Coverage with 35+ Exposures Mapped to Both OWASP Top 10 Frameworks</title>
      <link>https://permiso.io/blog/permiso-expands-ai-agent-security-coverage</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-expands-ai-agent-security-coverage" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/AI%20exposure%20mapping%20doc.png" alt="Permiso Expands AI Agent Security Coverage with 35+ Exposures Mapped to Both OWASP Top 10 Frameworks" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The question facing security teams is no longer whether AI agents introduce risk. It is what specifically to look for.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-expands-ai-agent-security-coverage" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/AI%20exposure%20mapping%20doc.png" alt="Permiso Expands AI Agent Security Coverage with 35+ Exposures Mapped to Both OWASP Top 10 Frameworks" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The question facing security teams is no longer whether AI agents introduce risk. It is what specifically to look for.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fpermiso-expands-ai-agent-security-coverage&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 11 Mar 2026 17:58:35 GMT</pubDate>
      <guid>https://permiso.io/blog/permiso-expands-ai-agent-security-coverage</guid>
      <dc:date>2026-03-11T17:58:35Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
    <item>
      <title>Permiso Security Named 2026 SC Awards Finalist for Best Threat Detection Technology</title>
      <link>https://permiso.io/blog/permiso-sc-awards-2026-best-threat-detection-technology</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-sc-awards-2026-best-threat-detection-technology" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/PR.png" alt="Permiso Security Named 2026 SC Awards Finalist for Best Threat Detection Technology" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Permiso Security has been named a finalist for Best Threat Detection Technology in the 2026 SC Awards&lt;/span&gt;. This is the &lt;span style="font-weight: normal;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/blog/permiso-named-sc-awards-finalist-in-two-categories" style="color: #0600ff;"&gt;second consecutive year Permiso has been recognized&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;in this category, and follows the company's win for &lt;span style="font-weight: normal;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="background-color: #ffffff; color: #0600ff;"&gt;&lt;a href="https://www.scworld.com/news/sc-awards-winner-2025-permiso-security-most-promising-early-stage-startup" style="background-color: #ffffff; color: #0600ff;"&gt;Most Promising Early-Stage Startup&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;at the 2025 SC Awards. Winners will be announced on March 24 during RSAC 2026 in San Francisco.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-sc-awards-2026-best-threat-detection-technology" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/PR.png" alt="Permiso Security Named 2026 SC Awards Finalist for Best Threat Detection Technology" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Permiso Security has been named a finalist for Best Threat Detection Technology in the 2026 SC Awards&lt;/span&gt;. This is the &lt;span style="font-weight: normal;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/blog/permiso-named-sc-awards-finalist-in-two-categories" style="color: #0600ff;"&gt;second consecutive year Permiso has been recognized&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;in this category, and follows the company's win for &lt;span style="font-weight: normal;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="background-color: #ffffff; color: #0600ff;"&gt;&lt;a href="https://www.scworld.com/news/sc-awards-winner-2025-permiso-security-most-promising-early-stage-startup" style="background-color: #ffffff; color: #0600ff;"&gt;Most Promising Early-Stage Startup&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;at the 2025 SC Awards. Winners will be announced on March 24 during RSAC 2026 in San Francisco.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fpermiso-sc-awards-2026-best-threat-detection-technology&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 03 Mar 2026 15:04:52 GMT</pubDate>
      <guid>https://permiso.io/blog/permiso-sc-awards-2026-best-threat-detection-technology</guid>
      <dc:date>2026-03-03T15:04:52Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
    <item>
      <title>Can an AI Agent Run a Purple Team Exercise?</title>
      <link>https://permiso.io/blog/can-an-ai-agent-run-a-purple-team-exercise</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/can-an-ai-agent-run-a-purple-team-exercise" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Screenshot%202026-02-11%20at%2011.56.46%20PM.png" alt="Can an AI Agent Run a Purple Team Exercise?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Two weeks ago, we deployed an AI agent to hunt malicious skills in the &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials" style="color: #0600ff;"&gt;OpenClaw ecosystem&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;. The agent, Rufio, found credential stealers, documented threat actors, and built detection rules. It accomplished its mission.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/can-an-ai-agent-run-a-purple-team-exercise" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Screenshot%202026-02-11%20at%2011.56.46%20PM.png" alt="Can an AI Agent Run a Purple Team Exercise?" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Two weeks ago, we deployed an AI agent to hunt malicious skills in the &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials" style="color: #0600ff;"&gt;OpenClaw ecosystem&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;. The agent, Rufio, found credential stealers, documented threat actors, and built detection rules. It accomplished its mission.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fcan-an-ai-agent-run-a-purple-team-exercise&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Research</category>
      <pubDate>Wed, 11 Feb 2026 18:54:31 GMT</pubDate>
      <guid>https://permiso.io/blog/can-an-ai-agent-run-a-purple-team-exercise</guid>
      <dc:date>2026-02-11T18:54:31Z</dc:date>
      <dc:creator>The Permiso Team</dc:creator>
    </item>
    <item>
      <title>Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything</title>
      <link>https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/image%20(9).png" alt="Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;We spun up an AI agent, gave it a mission to hunt threats, and watched it discover a credential stealer disguised as a weather app within minutes. That was just the beginning.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/image%20(9).png" alt="Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;We spun up an AI agent, gave it a mission to hunt threats, and watched it discover a credential stealer disguised as a weather app within minutes. That was just the beginning.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Finside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Research</category>
      <pubDate>Mon, 02 Feb 2026 17:55:22 GMT</pubDate>
      <guid>https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials</guid>
      <dc:date>2026-02-02T17:55:22Z</dc:date>
      <dc:creator>Ian Ahl</dc:creator>
    </item>
    <item>
      <title>Permiso Research Finds Up to 75% of Security Incidents Are Identity-Related, Highlighting New AI-Driven Risk</title>
      <link>https://permiso.io/blog/permiso-research-identity-security-incidents-ai-risk</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-research-identity-security-incidents-ai-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Blog%20Image%20(892%20x%20298)%20(2).png" alt="Permiso Research Finds Up to 75% of Security Incidents Are Identity-Related, Highlighting New AI-Driven Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="text-align: center; font-size: 18px; line-height: 1.75; font-weight: bold;"&gt;&lt;span style="color: #361292;"&gt;&lt;em&gt;Survey of 500+ Security &amp;amp; Identity Professionals Shows Dramatic 47-Point Drop in Visibility Confidence as 91% Expect Explosive Growth in &lt;/em&gt;&lt;em&gt;AI-Generated Identities in 2026&amp;nbsp;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-research-identity-security-incidents-ai-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Blog%20Image%20(892%20x%20298)%20(2).png" alt="Permiso Research Finds Up to 75% of Security Incidents Are Identity-Related, Highlighting New AI-Driven Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="text-align: center; font-size: 18px; line-height: 1.75; font-weight: bold;"&gt;&lt;span style="color: #361292;"&gt;&lt;em&gt;Survey of 500+ Security &amp;amp; Identity Professionals Shows Dramatic 47-Point Drop in Visibility Confidence as 91% Expect Explosive Growth in &lt;/em&gt;&lt;em&gt;AI-Generated Identities in 2026&amp;nbsp;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fpermiso-research-identity-security-incidents-ai-risk&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Press</category>
      <pubDate>Wed, 21 Jan 2026 12:12:10 GMT</pubDate>
      <guid>https://permiso.io/blog/permiso-research-identity-security-incidents-ai-risk</guid>
      <dc:date>2026-01-21T12:12:10Z</dc:date>
      <dc:creator>The Permiso Team</dc:creator>
    </item>
    <item>
      <title>Permiso State of Identity Security Report 2026: From False Confidence to True Visibility</title>
      <link>https://permiso.io/blog/permiso-state-of-identity-security-2026-survey-report</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-state-of-identity-security-2026-survey-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Blog%20Image%20(892%20x%20298)%20(1).png" alt="Permiso State of Identity Security Report 2026: From&amp;nbsp;False Confidence to True Visibility" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Permiso Security today released its &lt;span style="color: #0600ff;"&gt;&lt;a href="https://hero.permiso.io/state-of-identity-security-2026" style="color: #0600ff; text-decoration: underline;"&gt;2026 State of Identity Security Report&lt;/a&gt;&lt;/span&gt;, the third annual benchmark examining how organizations manage, secure, and gain visibility into identities across cloud environments. Based on responses from over 500 security and identity professionals worldwide, this year's findings reveal a sobering reality: the gap between what organizations believe they can see and what they actually control has never been wider.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/permiso-state-of-identity-security-2026-survey-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Blog%20Image%20(892%20x%20298)%20(1).png" alt="Permiso State of Identity Security Report 2026: From&amp;nbsp;False Confidence to True Visibility" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Permiso Security today released its &lt;span style="color: #0600ff;"&gt;&lt;a href="https://hero.permiso.io/state-of-identity-security-2026" style="color: #0600ff; text-decoration: underline;"&gt;2026 State of Identity Security Report&lt;/a&gt;&lt;/span&gt;, the third annual benchmark examining how organizations manage, secure, and gain visibility into identities across cloud environments. Based on responses from over 500 security and identity professionals worldwide, this year's findings reveal a sobering reality: the gap between what organizations believe they can see and what they actually control has never been wider.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fpermiso-state-of-identity-security-2026-survey-report&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Analysis</category>
      <pubDate>Wed, 21 Jan 2026 12:11:10 GMT</pubDate>
      <guid>https://permiso.io/blog/permiso-state-of-identity-security-2026-survey-report</guid>
      <dc:date>2026-01-21T12:11:10Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
    <item>
      <title>How to Choose the Best ITDR Solution for Your Organization</title>
      <link>https://permiso.io/blog/best-itdr-solution-for-your-organization</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/best-itdr-solution-for-your-organization" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Choose-Best-ITDR.png" alt="How to Choose the Best ITDR Solution for Your Organization" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The best &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/identity-threat-detection-and-response-solution" style="color: #0600ff;"&gt;ITDR solution&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; for your organization depends on measurable criteria rather than vendor claims: Can it track identities across authentication boundaries from your IdP through cloud infrastructure to SaaS applications? Does it generate high-fidelity alerts that your team actually investigates, or does it add to alert fatigue? Can it attribute activity when multiple users share service accounts? Does it draw on real-world threat intelligence or theoretical attack models? The vendor landscape ranges from established IAM providers adding detection capabilities to purpose-built platforms designed specifically for identity threat response, and choosing wrong means continuing to miss the attack technique behind the majority of successful breaches.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://permiso.io/blog/best-itdr-solution-for-your-organization" title="" class="hs-featured-image-link"&gt; &lt;img src="https://permiso.io/hubfs/Choose-Best-ITDR.png" alt="How to Choose the Best ITDR Solution for Your Organization" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The best &lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #0600ff;"&gt;&lt;a href="https://permiso.io/identity-threat-detection-and-response-solution" style="color: #0600ff;"&gt;ITDR solution&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; for your organization depends on measurable criteria rather than vendor claims: Can it track identities across authentication boundaries from your IdP through cloud infrastructure to SaaS applications? Does it generate high-fidelity alerts that your team actually investigates, or does it add to alert fatigue? Can it attribute activity when multiple users share service accounts? Does it draw on real-world threat intelligence or theoretical attack models? The vendor landscape ranges from established IAM providers adding detection capabilities to purpose-built platforms designed specifically for identity threat response, and choosing wrong means continuing to miss the attack technique behind the majority of successful breaches.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20407698&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fpermiso.io%2Fblog%2Fbest-itdr-solution-for-your-organization&amp;amp;bu=https%253A%252F%252Fpermiso.io%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Analysis</category>
      <pubDate>Tue, 06 Jan 2026 21:20:43 GMT</pubDate>
      <guid>https://permiso.io/blog/best-itdr-solution-for-your-organization</guid>
      <dc:date>2026-01-06T21:20:43Z</dc:date>
      <dc:creator>Aditya Vats</dc:creator>
    </item>
  </channel>
</rss>
