Cyera's $1B Oasis Acquisition Targets Non-Human AI Identities
Cyera has agreed to acquire Oasis Security for $1 billion to integrate non-human identity management and secure enterprise autonomous AI agents.
Cyera has acquired Oasis Security for approximately $1 billion in a mix of cash and stock. The transaction merges Cyera’s Data Security Posture Management platform with Oasis Security’s Non-Human Identity engine to secure the credentials and access rights of enterprise autonomous systems.
The Non-Human Identity Challenge
Internal telemetry from Cyera indicates that non-human identities outnumber human users by a 50-to-1 ratio in typical enterprise cloud environments. As organizations deploy specialized agents, the volume of active service accounts and API keys multiplies rapidly. If you implement multi-agent coordination, your infrastructure likely generates dozens of dynamic credentials per workflow. Unmanaged non-human identities create a vast attack surface for data breaches.
The proliferation of shadow AI compounds this vulnerability management challenge. Developers frequently provision unauthorized service accounts to test new models, leaving orphaned tokens with broad access rights in production environments. Securing this identity perimeter is now the primary attack vector defense for infrastructure administrators.
Cyera Platform Integration
The integration of Oasis Security allows the Cyera platform to automate the discovery, rotation, and lifecycle management of agent secrets. Administrators gain precise visibility into exactly what data a specific agent accesses, how it authenticates, and whether it holds excessive permissions. This ties data security policies directly to the machine identity making the request.
Oasis Security’s architecture maps the relationships between workloads, secrets, and cloud data stores. By incorporating this mapping into a posture management framework, Cyera programmatically enforces least-privilege principles. When an over-privileged agent attempts an irregular API call, the combined engine identifies the credential anomaly and can intervene before data leaks occur. Deployment of the integrated engine is scheduled for Q4 2026.
Strategic Market Consolidation
This marks Cyera’s third acquisition in 2026, following the $162 million purchase of Trail Security and the undisclosed acquisition of Bionic. The string of purchases follows Cyera’s Series D funding round earlier this year, which established a company valuation exceeding $3 billion.
The Oasis Security founding team and engineering staff will transition to Cyera’s research and development centers in New York and Tel Aviv. Enterprise environments are actively shifting from human-centric access controls to systems that can monitor AI applications and their associated machine credentials at scale. Non-human identity management is currently the fastest-growing segment of the Identity and Access Management sector.
If you deploy autonomous systems in production, audit your service accounts and secret rotation policies immediately. Transition away from static API keys toward dynamic, short-lived credentials scoped strictly to specific tasks and data access requirements.
Get Insanely Good at AI
The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.
Keep Reading
How to Deploy Claude Code Auto Mode in Production
Learn how to configure Claude Code's auto mode to run unattended agent workflows, set up defense-in-depth tool guards, and manage the safety classifier.
Vague Task Definitions Drive 65% of Agent Security Incidents
Token Security reveals that broad permissions and vague prompts are causing a surge in autonomous AI overreach across 65% of surveyed enterprises.
Persistent Grok Bot Swarms Access Apps via Shared Linux VMs
SpaceXAI's new Grok Bot beta introduces always-on AI agents that navigate workplace applications autonomously through shared persistent cloud environments.
Nvidia Updates NeMo to Support OSAIA Agent Security Draft
The Open Secure AI Alliance released its first technical framework for autonomous agent security alongside immediate API updates to Nvidia's NeMo and NIM.
$180M Backs Glow's Server-Side Endpoint Defense for AI Agents
Cybersecurity startup Glow has emerged from stealth with $180 million in funding to shift enterprise endpoint defense to a server-side prevention model.