
Two of Three: MolTrust Closes RSAC 2026's Open Agent Security Gaps
RSAC 2026 shipped five agent identity frameworks this week. Three critical gaps remained open across all of them. We closed two. What RSAC showed us Every major security vendor had an agent identity story. Cisco shipped agent governance. CrowdStrike announced AI agent monitoring. Microsoft extended Entra to non-human identities. Palo Alto demoed runtime agent controls. Then CrowdStrike's CEO disclosed two Fortune 50 agent-initiated incidents — both discovered by accident. Censys showed 500,000 publicly exposed OpenClaw instances. The pattern: the industry can verify who an agent is. Nobody was tracking what the agent actually did. Gap 2 — Delegation without verification A 100-agent swarm runs a deployment pipeline. Agent 12 makes the commit. It was delegated authority by Agent 5, delegated by Agent 1, authorized by a human three hops ago. Can you verify that chain cryptographically? No OAuth, SAML, or MCP has a delegation primitive for agent-to-agent. MolTrust fix: verifyDelegationChai
Continue reading on Dev.to
Opens in a new tab



