Cyera's $1B Oasis Acquisition Targets Non-Human AI Identities
Cyera has agreed to acquire Oasis Security for $1 billion to integrate non-human identity management and secure enterprise autonomous AI agents.
Cyera has acquired Oasis Security for approximately $1 billion in a mix of cash and stock. The transaction merges Cyera’s Data Security Posture Management platform with Oasis Security’s Non-Human Identity engine to secure the credentials and access rights of enterprise autonomous systems.
The Non-Human Identity Challenge
Internal telemetry from Cyera indicates that non-human identities outnumber human users by a 50-to-1 ratio in typical enterprise cloud environments. As organizations deploy specialized agents, the volume of active service accounts and API keys multiplies rapidly. If you implement multi-agent coordination, your infrastructure likely generates dozens of dynamic credentials per workflow. Unmanaged non-human identities create a vast attack surface for data breaches.
The proliferation of shadow AI compounds this vulnerability management challenge. Developers frequently provision unauthorized service accounts to test new models, leaving orphaned tokens with broad access rights in production environments. Securing this identity perimeter is now the primary attack vector defense for infrastructure administrators.
Cyera Platform Integration
The integration of Oasis Security allows the Cyera platform to automate the discovery, rotation, and lifecycle management of agent secrets. Administrators gain precise visibility into exactly what data a specific agent accesses, how it authenticates, and whether it holds excessive permissions. This ties data security policies directly to the machine identity making the request.
Oasis Security’s architecture maps the relationships between workloads, secrets, and cloud data stores. By incorporating this mapping into a posture management framework, Cyera programmatically enforces least-privilege principles. When an over-privileged agent attempts an irregular API call, the combined engine identifies the credential anomaly and can intervene before data leaks occur. Deployment of the integrated engine is scheduled for Q4 2026.
Strategic Market Consolidation
This marks Cyera’s third acquisition in 2026, following the $162 million purchase of Trail Security and the undisclosed acquisition of Bionic. The string of purchases follows Cyera’s Series D funding round earlier this year, which established a company valuation exceeding $3 billion.
The Oasis Security founding team and engineering staff will transition to Cyera’s research and development centers in New York and Tel Aviv. Enterprise environments are actively shifting from human-centric access controls to systems that can monitor AI applications and their associated machine credentials at scale. Non-human identity management is currently the fastest-growing segment of the Identity and Access Management sector.
If you deploy autonomous systems in production, audit your service accounts and secret rotation policies immediately. Transition away from static API keys toward dynamic, short-lived credentials scoped strictly to specific tasks and data access requirements.
Get Insanely Good at AI
The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.
Keep Reading
How to build ordering agents with DoorDash dd-cli
Learn how to configure the new DoorDash dd-cli to enable autonomous food ordering and real transaction processing for your AI workflows.
$180M Backs Glow's Server-Side Endpoint Defense for AI Agents
Cybersecurity startup Glow has emerged from stealth with $180 million in funding to shift enterprise endpoint defense to a server-side prevention model.
Rakuten Speeds Up Agent Workflows 10x Using Claude Fable 5
Anthropic detailed how Rakuten uses Claude Fable 5 to automate multi-step software engineering tasks, resulting in a 10x speedup for complex workflows.
SivaClaw Agent Compresses $100M Fundraise Cycle to Two Weeks
Lyzr deployed its internal AI agent to manage its $100 million Series B fundraise, securing $400 million in investor interest while bypassing human associates.
JadePuffer Ransomware Deploys Autonomous Llama 4 Cyberattack
The JadePuffer ransomware attack marks the first confirmed use of an autonomous LLM agent executing an end-to-end cyberattack without human intervention.