Skip to content
AppSec Santa Weekly

#8 — The Next AppSec Boundary Isn't Code vs. Cloud. It's Human vs. Non-Human.

Non-human identities (NHIs) — CI tokens, publisher accounts, OAuth grants, agent sessions — are now the primary AppSec attack surface. Mini Shai-Hulud (Apr 2026) and Cisco's $400M Astrix deal (May 2026) prove it.

| 4 min read

Want this in your inbox?

Every Tuesday, no spam.

Subscribe