The Control Plane for Agentic Identity. Discover, explain, and control every AI Agent in your organization, turning unseen risk into your competitive advantage.

Joined June 2025
10 Photos and videos
Cyata retweeted
๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐˜„๐—ถ๐—น๐—น ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ณ๐—ฎ๐˜€๐˜ ๐—ถ๐—ป ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ. ๐—”๐—ฟ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐—ฟ๐—ฒ๐—ฎ๐—ฑ๐˜†? We are moving from identity governance built for slow human actions to a world where agents execute autonomous actions at machine speed. In our new research, we introduce Agentic Identity Access Platforms (AIAP): an end-to-end architecture that acts like a new SSO for agents, shifting governance from who logged in to why an action is happening, with task-scoped identities and permissions issued only when an authorized action is requested or in progress. We partnered with 5 vendors pushing this ecosystem forward: 1๏ธโƒฃ @AstrixSecurity 2๏ธโƒฃ @oasissec 3๏ธโƒฃ @aembit_io 4๏ธโƒฃ @TeamCyata 5๏ธโƒฃ @silverfort Full report with case studies, implementation patterns, and our new ecosystem map: softwareanalyst.substack.comโ€ฆ
7
24
2,838
Cyata retweeted
๐ŸŽ‰ @CheckPointSW is acquiring @TeamCyata to accelerate its mission of delivering an end-to-end AI security platform for the agentic world. As AI systems shift from prompts to autonomous action, agents are already operating across browsers, IDEs, SaaS, and internal environments, often with limited visibility and control. Cyata built technology to discover, understand, and govern autonomous AI agents, with guardrails and posture controls designed specifically for this new layer. We are proud to have backed the Cyata team from day one, and to see their vision and technology become the foundation of Check Pointโ€™s AI security platform. @jifa @brian_sack3
2
4
264
Feb 11
AI agents are already making decisions across your organization. But most security teams have no visibility into what they're actually doing, and can't control them when they go rogue. Shahar Tal (@jifa) joined @i24NEWS_EN to discuss the new security challenge most enterprises aren't prepared for: autonomous AI systems acting without oversight. Watch the full conversation on agentic security and how to bring autonomous AI under control:
1
4
125
Jan 20
๐Ÿ”“ Cyata Research disclosed three vulnerabilities in ๐€๐ง๐ญ๐ก๐ซ๐จ๐ฉ๐ข๐œ'๐ฌ ๐จ๐Ÿ๐Ÿ๐ข๐œ๐ข๐š๐ฅ ๐†๐ข๐ญ ๐Œ๐‚๐ ๐ฌ๐ž๐ซ๐ฏ๐ž๐ซ. Each flaw looked relatively moderate in isolation. But chain them together with the Filesystem MCP server, and you get remote code execution - triggered entirely through prompt injection. The real takeaway โ†’ as agentic systems get more complex, it's the combinations that break things. Tooling that looks safe in isolation can become dangerous when chained together. ๐Ÿ“ฐ Read theย coverage by The Register: theregister.com/2026/01/20/aโ€ฆ ๐Ÿ“ Full technical writeup in the first comment.
1
3
108
26 Dec 2025
๐Ÿšจย ๐–๐ž ๐Ÿ๐จ๐ฎ๐ง๐ ๐š ๐œ๐ซ๐ข๐ญ๐ข๐œ๐š๐ฅ ๐ฏ๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ฒ ๐ข๐ง ๐‹๐š๐ง๐ ๐‚๐ก๐š๐ข๐ง. Upgrade to langchain-core 1.2.5 or 0.3.81 immediately. Cyata's security researcher Yarden Porat discovered LangGrinch (CVE-2025-68664 & CVE-2025-68665): the first critical vulnerability in LangChain Core, the most widely adopted framework for building AI agents (847M total downloadsย per pepy.tech). The flaw lives in core serialization logic, making it reachable across virtually any deployment. The attack:ย Malicious inputs can trick LangChain into leaking secrets from your environment, no direct code access required. Full technical breakdown โ†’ cyata.ai/blog/langgrinch-lanโ€ฆ Coverage by @SiliconANGLE โ†’ siliconangle.com/2025/12/25/โ€ฆ This is what securing agentic AI looks like. The agent isn't just the asset, it's the attack surface.
3
12
787
19 Dec 2025
๐๐ž๐ฐ ๐ซ๐ž๐ฌ๐ž๐š๐ซ๐œ๐ก ๐Ÿ๐ซ๐จ๐ฆ ๐‚๐ฒ๐š๐ญ๐š: ๐‚๐•๐„-๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“-๐Ÿ”๐Ÿ’๐Ÿ๐ŸŽ๐Ÿ” Cyata security researcher Yarden Porat disclosed a high-severity RCE vulnerability in Cursor's MCP installation flow. A single keyword in a deep-link bypassed the security modal, presenting users with a trusted dialog while executing attacker-controlled commands. The finding highlights a systemic gap: AI IDEs are making undocumented trust decisions that security teams have no way to audit. This exception was found through reverse-engineering raising the question of what other trust shortcuts exist across agentic tooling. Full coverage in SiliconANGLE: siliconangle.com/2025/12/19/โ€ฆ
1
3
141
18 Dec 2025
๐˜๐จ๐ฎ๐ซ ๐ˆ๐€๐Œ ๐ฌ๐ฒ๐ฌ๐ญ๐ž๐ฆ ๐ข๐ฌ ๐Ÿ๐š๐ฌ๐ญ. ๐˜๐จ๐ฎ๐ซ ๐€๐ˆ ๐š๐ ๐ž๐ง๐ญ๐ฌ ๐š๐ซ๐ž ๐Ÿ๐š๐ฌ๐ญ๐ž๐ซ. Employee terminated at 2:47:00 PM. By 2:48:00 PM, their agent has accessed critical systems across three cloud environments-before the revocation fully propagates. In a guest post, Sushant Chowdhary (Ascension) breaks down why State Drift in "eventually consistent" IAM becomes an instant attack vector when agents operate at machine speed, and what replaces it. Worth the read: cyata.ai/blog/speed-kills-whโ€ฆ
3
63
22 Nov 2025
Weโ€™re excited to announce that Cyata will be exhibiting at The AI Summit New York this December - find us at booth S1! As organizations embrace AI agents across their operations, visibility and control are critical. Cyataโ€™s control plane for agentic identity gives teams the power to discover, explain, and control every AI agent, ensuring secure and governed adoption at scale. ๐Ÿ“ Visit us at booth S1 during hashtag#TheAISummit New York. ๐Ÿ‘‰ Book a dedicated meeting with our team: cyata.ai/ai-summit-ny/
1
2
162
19 Nov 2025
Google just launched Antigravity. ๐—ช๐—ฒ ๐˜€๐—ต๐—ถ๐—ฝ๐—ฝ๐—ฒ๐—ฑ ๐—ณ๐˜‚๐—น๐—น ๐˜€๐˜‚๐—ฝ๐—ฝ๐—ผ๐—ฟ๐˜ ๐—ถ๐—ป ๐—–๐˜†๐—ฎ๐˜๐—ฎ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฒ ๐—ต๐—ผ๐˜‚๐—ฟ๐˜€ ๐—น๐—ฎ๐˜๐—ฒ๐—ฟ. That's not bragging - it's the point. Agentic tools will keep arriving. Security needs a control plane that moves at their speed. New blog on Antigravity, Agent Modes, and why same-day support matters: cyata.ai/blog/google-antigraโ€ฆ
1
2
4
216
18 Nov 2025
Proud to announce Cyata has joined @owasp. When AI agents become critical infrastructure, securing them requires open standards and community collaboration to establish the security paradigm organizations need today. Read more on our blog: cyata.ai/blog/cyata-joins-owโ€ฆ
1
2
92
16 Nov 2025
๐„๐ฑ๐œ๐ข๐ญ๐ž๐ ๐ญ๐จ ๐ฌ๐ก๐š๐ซ๐ž ๐ญ๐ก๐š๐ญ ๐‚๐ฒ๐š๐ญ๐š ๐ฐ๐ข๐ฅ๐ฅ ๐›๐ž ๐ž๐ฑ๐ก๐ข๐›๐ข๐ญ๐ข๐ง๐  ๐š๐ญ ๐ญ๐ก๐ž ๐†๐š๐ซ๐ญ๐ง๐ž๐ซ ๐ˆ๐๐ž๐ง๐ญ๐ข๐ญ๐ฒ & ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ ๐’๐ฎ๐ฆ๐ฆ๐ข๐ญ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“ ๐ญ๐ก๐ข๐ฌ ๐ƒ๐ž๐œ๐ž๐ฆ๐›๐ž๐ซ ๐ข๐ง ๐“๐ž๐ฑ๐š๐ฌ! As AI agents become the new workforce, identity governance must evolve. Cyata enables organizations to discover, explain, and control every AI agent with posture-first identity security. ๐Ÿ“ Visit us at Booth #725 in the exhibit hall ๐Ÿ‘‰ย Book a meeting with our team: cyata.ai/gartner-iam/
1
3
86
5 Nov 2025
Every computing era demanded its own security discipline. Now autonomous agents demand theirs. Introducing Agentic SPM. AI agents aren't users. They're not NHIs. They're autonomous actors that reason, decide, and act. Existing security can't govern them. Agentic Security Posture Management can. Read why: cyata.ai/blog/why-aispm-isntโ€ฆ
1
3
197
22 Oct 2025
Cyata has officially joined the Cloud Security Alliance and signed the AI Trustworthy Pledge. As AI agents become autonomous actors in enterprise environments, we're committed to supporting open, community-driven standards for AI agent governance. Read more in our latest blog: cyata.ai/blog/cyata-joins-clโ€ฆ @cloudsa
2
146
12 Aug 2025
Iโ€™m not here to tell you to secure your AI agents. And I definitely wonโ€™t say theyโ€™re the most powerful identities in your environment. Orโ€ฆ that they can make your attack surface look enormous. Why would I need to do that? But if you said you wanted to see them - and lock down their privileges - Iโ€™m not gonna stop you. But just to be clear, this is not me telling you to secure your AI agents. You see what I did there, right?
3
1
19
1,711
7 Aug 2025
Vaults are trusted by default. We found 14 zero-days that challenge that trust. RCEs. Auth bypass. Root token theft. ๐Ÿ”ŽRead the disclosure: cyata.ai ๐ŸŽ™๏ธ See us at #BlackHat2025 Booth 6316 #VaultFault #Cybersecurity #ZeroDay #CISO #HashiCorpVault #CyberArk #Infosec
1
2
19
3,420
30 Jul 2025
๐Ÿšจ @Cyata is out of stealth! $8.5M seed backed by @TLV_Partners & security leaders from @Cellebrite, Unit 8200 & @CheckPointSW. Weโ€™re building the Control Plane for Agentic Identity - securing AI agents with visibility, auditing & just-in-time controls. venturebeat.com/security/howโ€ฆ
1
2
21
860
1 Jul 2025
Theyโ€™re not malicious. Theyโ€™re just agentic.
11
610