# Two small bugs, nine CVEs, and a role you can't audit

Canonical: https://brew.new/browse/templates/email/pt1_k97ht8648yxdapf7tj27a2axed8e5p04

Brand: goteleport.com
Category: newsletter

![Preview of Two small bugs, nine CVEs, and a role you can't audit](https://cdn.brew.new/email-preview-910059a313884dda-tracking_r57yqk6wxfzpv8p730d1qk65b98dvj0n-1789006044333.png)

## Email content

Teleport

New in Identity

Teleport — New in Identity - Issue #9

Most access failures do not start with a breach. They start with a shortcut that looks reasonable: an extra role to unblock a team, a credential parked in a secrets manager, a library trusted because everyone uses it. This issue follows three of those shortcuts to where they end up. One becomes a critical vulnerability, one becomes a role count nobody can explain, and one becomes a regulator asking for evidence you cannot produce.

AI agents at scale behave like nothing else running on your infrastructure, and zero trust as currently conceived is necessary but not sufficient to contain them. A new white paper sets out what has to change to preserve trust as agents are deployed across enterprise infrastructure.

Read the From Zero Trust to Agent Trust white paper →

How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go’s SSH Library

By Rob Picard

Two individually harmless bugs combined into the first critical vulnerability in Teleport in a decade, and the follow-on review of Go's x/crypto/ssh produced nine more CVEs. Neither bug was exploitable alone. One accepted an SSH certificate where only a CA key belongs, the other let that certificate be passed to the library as an authority. The post traces how the two met, and why the answer was an external cryptographic audit rather than a quiet patch.

Read the full post →

How to Prevent RBAC Role Explosion with Nested Access Lists

By Paul Curtis

Role explosion is the point where an organization's role count outpaces its actual user count, and every login still has to be checked against all of them. The cause is mundane. Editing a shared role risks changing access for everyone who holds it, so admins clone it instead. At 200 Kubernetes clusters with 15 to 20 namespaces each, handling access team by team stops being viable, and nested access lists carry permissions by inheritance so roles can stay fixed and few.

Read the full post →

Navigating SAMA, ADGM & DFSA Requirements with Teleport

By Mukund Cadambi

Gulf financial regulators now specify access controls down to the section number. SAMA's Cyber Security Framework calls for centralized IAM with a comprehensive audit trail in 3.3.5, and ADGM asks for approval workflows, prompt revocation, and recurring access reviews in 3.5.7. Entry into Saudi Arabia and the UAE often turns on meeting those rules rather than on holding a commercial certification. Long-lived credentials, VPNs, and per-platform access controls are what make that evidence hard to centralize and harder to show a regulator.

Read the full post →

Have questions or want to keep the conversation going? Join us in our Community Slack →

If you found this useful, pass it along to someone else who would, too.

Thanks for reading,

The Teleport Editorial Team

P.S. We'll be at these events over the next few weeks. Come find us.

Sep 1: KCD SF, Mountain View, CA

Sep 7: CPX GISEC, Dubai

Sep 15: AI Infra Summit, Santa Clara, CA

Sep 16: DCD Connect London

Sept 17: Teleport Identity Security for AI Webinar Virtual

Sept 24: Teleport Identity Summit Mountain View, CA

Sept 30: Teleport Identity Summit New York, NY

Find us near you: https://goteleport.com/events/

Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612

If you no longer wish to receive these emails anymore, click on the following link:

UNSUBSCRIBE

TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97ht8648yxdapf7tj27a2axed8e5p04)

[Browse email designs](https://brew.new/browse/templates)
