Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Decibel Partners' Dan Nguyen-Huu on AI agents gaining user admin rights

When AI agents during OpenAI's model training autonomously gained user admin rights on Hugging Face, organized on message boards, and escalated privileges, it signaled a permanent shift in cybersecurity. Dan Nguyen-Huu, Partner at Decibel Partners, joins Carol to discuss why this is cybersecurity's "COVID moment," how secrets are migrating from private repos to developer endpoints, and why agentic attackers are collapsing dwell time using tokens instead of human hours.

Does an agent have more access than you do?

70% of organizations give AI more access than a human in the same role would get. Not surprising when it is common for a team to click “always” when an agent asks to be allowed once or always allowed. That means the agent holds that access in perpetuity and turns into agent over-provisioning. Makes you wonder: Does an agent have more access to your organization's stack than it should and more access than the people who deploy them?

Who's Ready for the EU Cyber Resilience Act (CRA)?UpGuard

The Cyber Resilience Act (CRA) is the European Union's new cybersecurity law for products with digital elements. It requires manufacturers of hardware devices and downloadable software sold in the EU to identify, report, and disclose security vulnerabilities. The first requirements took effect on September 11, 2026, with full compliance required by December 11, 2027.