MCP & Agent Identity
Related: AI Security, Identity, Security for AI, AI for Offense.
On May 4, 2026, Cisco announced its intent to acquire Astrix Security — a non-human-identity (NHI) startup — for a reported ~$400M (Cisco blog; Calcalist), its third cybersecurity acquisition of 2026 after Galileo and ahead of WideField Security (Jun 18 2026). Astrix had raised ~$85M total (including a $45M Series B in Dec 2024 from CRV and Menlo Ventures), so the reported price is a substantial strategic premium for a company most enterprise buyers had not yet deployed at scale. (Reported intent, subject to closing.) The rationale reflects a structural shift AI is forcing on the identity market: every AI agent is a new identity that must be authenticated, scoped, monitored, and revoked — and there are about to be far more of them than there are humans. This shift, and the protocol layer (Model Context Protocol) that makes it urgent, are the subject below. The broader identity market sits on 03a; the new AI attack surface is 03l.
What a non-human identity is
A non-human identity is any credentialed actor that is not a person: a service account, an API key, an OAuth token, a machine certificate, a CI/CD secret, a service-mesh workload — and now, an AI agent. NHIs already vastly outnumber human identities in the enterprise; the commonly cited ratio is on the order of 45–50 non-human identities for every human (estimate; figures vary 40:1 to 100:1 by source and environment). They are also the worse-governed half of the identity estate: secrets get hard-coded, tokens never expire, service accounts accrete permissions no one revokes, and most never appear in the joiner-mover-leaver lifecycle that governs human accounts. NHIs were already the leading breach vector in cloud environments before agents arrived.
AI agents make the problem categorically worse along three axes:
- Volume. An agentic workflow can spawn many short-lived agent and sub-agent identities, each needing credentials to call tools, APIs, and data stores. The NHI population stops being a stock and becomes a flow.
- Autonomy. A human's actions are bounded by what a human can do per hour. An agent acts at machine speed and can chain tool calls — so an over-permissioned agent identity is a far larger blast radius than an over-permissioned human.
- Delegation ambiguity. When an agent acts "on behalf of" a user, whose authority is it exercising, and within what scope? Traditional IAM has no clean answer. This is the agent-identity problem proper.
The agentic identity lifecycle
MCP — the protocol layer
Model Context Protocol (MCP), the open standard Anthropic introduced in late 2024, is the USB-C of agentic AI: a uniform way for an AI agent to connect to tools, data sources, and external systems via "MCP servers." Adoption exploded through 2025–2026 because it solved a real integration problem — but it also created a new, poorly-secured trust boundary. An agent that can call arbitrary MCP servers can be steered by whatever those servers return. The recognized MCP attack classes now include:
- Prompt / tool-description injection — a malicious MCP server embeds instructions in tool metadata or returned data that hijack the agent's plan ("tool poisoning").
- Confused-deputy & token passthrough — the agent's broad credentials are abused by a downstream server the user never intended to authorize.
- MCP server vulnerabilities — a compromised or vulnerable server becomes RCE. At RSA Conference 2026, researchers demonstrated a full Azure-tenant takeover chained through an MCP vulnerability and remote code execution — the live demo that pushed MCP security from theory to boardroom.
MCP makes the agent-identity problem concrete: each MCP connection is a delegation decision, and most early deployments grant agents standing, over-broad credentials with no scoping, expiry, or audit. Securing MCP is securing agent identity plus the data/tool boundary.
Agent-mediated bypass of existing controls
The delegation problem described above has a demonstrated attack pattern. At DEF CON 2026 in Las Vegas on August 9, 2026, researchers from Tenet Security presented a technique they call Ghostjacking, positioned as the next stage of the earlier Agentjacking class, in which an AI coding agent is induced to execute arbitrary code on a developer's machine. Ghostjacking's distinguishing property is that it requires no new privilege. The attacker plants content that an agent will later read as ordinary operational data; the agent then acts on that content using access it has already been granted. No control fails and nothing anomalous appears at the credential layer, because at that layer nothing anomalous occurs.
Three platforms were used to demonstrate the pattern, none of them a security product:
- Web application firewall logs. When a managed rule blocks a malicious request, it records the request verbatim. An agent asked to review blocked events reads the planted entry as a genuine finding, rewrites the organization's DNS to point the domain at the attacker, and reports the issue resolved — after which web and email traffic can be rerouted. The blocking control is the delivery path. Against Anthropic's Claude Code on the platform vendor's own recommended configuration, the researchers reported the chain succeeding in nine of ten attempts.
- Application-performance monitoring. A client-side key intended only for a website's front end is routinely left public; the researchers identified more than 2,700 such keys. The key permits an attacker to plant an urgent-looking diagnostic alert, which an agent reads when an engineer asks it to check for errors.
- Error tracking. The platform's own AI feature reads the attacker's fabricated report and fabricated fix, adopts them as its own conclusion, and passes that conclusion to a coding agent, which trusts it and runs the code — one automated system vouching for the attacker to another.
The platforms named were Cloudflare, Datadog and Sentry; the researchers disclosed to all three in June 2026 and characterized the three cases as one shape rather than three separate flaws — wherever an AI reads outside data it trusts and can also act on that data, the boundary is open. Other pairings named as carrying the same shape include a log-analytics platform with a build system and an APM platform with a container orchestrator.
Scale is what makes the finding a market fact rather than only a technical one. Tenet's estimate is that half of the Fortune 500 are exposed. The footprints behind that estimate are large and overlapping: the edge provider is reported to run in about 42% of the Fortune 500 and to carry a fifth of all internet traffic, the APM vendor in about 48%, and the error-tracking tool to be used by about four million developers — figures that describe the same enterprises repeatedly and therefore cannot be added. Organizations running the exposed configuration were not identified and were described only by type.
Two consequences follow for the market covered on this page. The first is demand formation. The recommended mitigations — deny outbound network access by default, require human approval for any command an agent executes, prevent data an agent reads from becoming an instruction it runs, and treat every reachable token as at risk while inventorying every tool an agent connects to — correspond to stages 3 and 4 of the lifecycle above, and they are architectural rather than model-level, which is the portion of the problem that agent-identity and agent-runtime vendors sell against. The second is buyer identification. The systems carrying the exposure belong to observability, error-tracking and edge-delivery vendors (42a, 42e), which hold both the deployment footprint and the telemetry needed to add the control themselves, and which therefore belong alongside the identity and data-security platforms in the buyer universe for this category (11b).
Sources: Tenet Security — Ghostjacking and the agentic kill chain · Infosecurity Magazine — "Ghostjacking" Exploits AI Agents' Trusted Access to Evade Firewall Controls (Aug 10, 2026)
The named landscape
| Actor | What it does | How it makes money | M&A status / relevance |
|---|---|---|---|
| Astrix Security | NHI + AI-agent discovery, governance, lifecycle, secrets | SaaS platform subscription | Cisco intent to acquire ~$400M (announced May 4 2026; subject to closing) — the category's marquee exit |
| Oasis Security | NHI lifecycle management & posture for agents | SaaS subscription | Acquired by Cyera for ~$1B (announced Jul 28 2026; completed Sep 3 2026; ~$700M cash + Cyera stock) — the largest NHI/agent-identity exit to date; had raised ~$195M ($120M Series B Mar 19 2026), the largest pure NHI round, so the price is ~5.1x capital raised on a gross, pre-dilution basis. Now operates as Cyera Identity. A data-security platform absorbing agent identity |
| Aembit | Secretless workload IAM; cryptographic attestation via an Edge sidecar | Workload-IAM subscription | Independent; differentiates on no secrets — verify, don't store |
| Token Security | NHI + machine/agent identity security | SaaS subscription | Well-funded independent; agent-identity positioning |
| Entro Security | NHI & secrets security | (acquired) | Acquired by SailPoint — identity-governance leader bolting on NHI (03a) |
| Clutch Security · GitGuardian · Natoma · Britive | NHI discovery, secrets detection, just-in-time NHI access | SaaS / consumption | The independent field; consolidation candidates |
| CyberArk (now PANW) | Secrets management + machine identity at platform scale | Platform | The incumbent control point — agent identity folds into the PANW–CyberArk platform |
The falsifiable bear case
Three ways the "agent identity is a durable standalone market" thesis could disappoint. First, it is a feature, not a market: NHI/agent identity may be absorbed wholesale into the identity and data-security platforms (Okta, Microsoft Entra, PANW-CyberArk, SailPoint, Cyera) the moment they ship native agent governance — Cisco buying Astrix, SailPoint buying Entro, Cyera buying Oasis (~$1B, Jul 2026), and Okta buying Permiso (ITDR across human, machine and agent identities, Jul 30 2026) are evidence for this absorption, not against it, and they leave little room for standalone scale. Okta's move also extends the pattern from identity issuance into identity detection: the platforms are absorbing both the credentials the agents carry and the runtime monitoring of how those credentials behave. Keyfactor buying Cofide (Jul 27 2026, SPIFFE-based workload/agent identity) is the issuance counterpart — a machine-identity/PKI incumbent absorbing the layer that hands each agent a short-lived verified identity. Second, the protocol layer standardizes the problem away: if MCP, OAuth working groups, and the model providers bake scoped, delegatable, expiring agent credentials into the protocol and the platforms themselves, the third-party "agent IAM" layer thins out. Third, agent adoption underdelivers: if enterprise agentic deployment stays in pilot (as much of the 04c autonomous-SOC market still is), the NHI explosion is slower than the funding implies, and 2026's valuations look early. The falsification data: watch whether the remaining independents (Aembit, Token) reach durable eight-figure ARR before the platforms ship credible native agent governance — Oasis, the most-funded pure NHI vendor, exited to Cyera before that question was settled.
→ & angle
Sources: Cisco — intent to acquire Astrix Security (blog, May 4 2026); Cisco to acquire Astrix for ~$400M — Calcalist/Ctech; Astrix $45M Series B — GovInfoSecurity (Dec 2024); Oasis Security $120M Series B — Bloomberg, Mar 19 2026; Oasis $120M — GovInfoSecurity; NHI platform comparison 2026 — GitGuardian; RSAC 2026 NHI report — Cremit.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.