< ciso
brief />
Tag Banner

All news with #agent security tag

336 articles · page 9 of 17

AI Agents Inside Your Perimeter: Visibility & Control

🛡️ Analysts and Orchid Security warn that enterprises are deploying AI agents faster than governance can keep up, creating an invisible layer of "identity dark matter" that conventional IAM misses. Orchid Security inspects applications at the binary and configuration layer to discover agents, audit compliance, and locate static credentials. Its Ask Orchid assistant answers natural-language questions about active agents, NIST compliance, and credential risks, then recommends prioritized remediation. This in-application observability aims to close the structural gap in identity visibility and enforce purpose-bound, least-privilege controls.
read more →

Amazon Quick Integrates New Relic AI Agents for Observability

🤖 Amazon Quick now integrates with New Relic's AI agents, enabling on-call engineers, SREs, and engineering leaders to investigate incidents, run NRQL queries, and generate evidence-backed RCAs directly within the Quick workspace. After connecting to New Relic’s remote model context protocol (MCP) server, users can invoke alert insights, log analysis, transaction diagnostics, and user-impact assessments from a conversational prompt. Quick Flows can automate recurring triage runbooks or escalation steps, and responses are surfaced alongside enterprise knowledge in Spaces for context-aware outcomes. The integration is available in all AWS Regions where Amazon Quick operates.
read more →

Cloud Engineers AI Toolkit: Hands-on Developer Workshops

🤖 Join hands-on developer workshops across North America that teach secure, scalable deployment of agentic AI for enterprises. These sessions are practical, bring-your-laptop labs where Platform, Security, and Data practitioners build end-to-end solutions, including GKE cluster hardening, secure sandboxing, and governed data pipelines. Tracks cover GKE + Data and Data Engineering & Analytics, with guidance from Google experts. Attendees leave with runnable labs and operational best practices to accelerate production adoption.
read more →

Agent Factory Recap: Gemma 4 Brings Agentic AI to Devices

🤖 Gemma 4, released by Google DeepMind, is a new family of open models optimized for local and mobile deployment. The family emphasizes intelligence per parameter, offering ultra-mobile E2B/E4B sizes, a 31B dense model for local GPUs, and a 26B Mixture-of-Experts variant. The shift to an Apache 2 license plus tools like the Agent Development Kit enables offline agentic workflows and commercial use by developers and startups.
read more →

Firestore expands agentic AI, full-text search, MongoDB

🚀 At Google Cloud Next '26, Firestore introduced expanded agentic AI integrations, built-in full-text search, and deeper MongoDB compatibility aimed at accelerating agent-driven applications. The Enterprise edition’s reimagined query engine adds hundreds of expressive query features, JOINs via subqueries, and pipeline operations. Native connections to AI Studio and third-party coding agents plus preview tools like natural language console querying and Usage Insights simplify building agentic workflows. These capabilities are available now in Firestore Enterprise in both Native and MongoDB compatibility modes.
read more →

Microsoft Agent 365 Now GA: Expanded Agent Controls

🔒 Microsoft announces Agent 365 is generally available, offering a unified control plane to observe, govern, and secure AI agents across endpoints, cloud, and SaaS. The release adds discovery of local and cloud agents (including OpenClaw, GitHub Copilot CLI, and Claude Code) and integrates with Intune and Defender for inventory, policy controls, runtime blocking, and alerting. Agent 365 also introduces Windows 365 for Agents, partner integrations, and licensing via Microsoft 365 E7 or standalone at USD 15 per user per month.
read more →

Guidance for Careful Adoption of Agentic AI Services

🛡️ CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other partners, released guidance to help organizations adopt agentic AI systems safely. The guide identifies key security challenges and risks and offers actionable steps for designing, deploying, and operating these systems. It emphasizes risk management, alignment with existing cybersecurity frameworks, and strengthened oversight to help security teams, developers, and decision-makers implement practical governance and controls.
read more →

Guide: Secure Adoption of Agentic AI — CISA and Partners

🔒 CISA, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD ACSC), and U.S. and international partners published Careful Adoption of Agentic Artificial Intelligence Services, a joint guide describing cybersecurity challenges and mitigations for agentic AI. The document warns that agentic AI can expand attack surface, cause privilege creep, produce behavioral misalignment, and obscure event records while offering automation benefits to critical infrastructure and defense sectors. It targets developers, vendors, and operators with actionable recommendations — including avoiding broad or unrestricted access to sensitive data and systems, beginning with low‑risk, non‑sensitive use cases, and explicitly accounting for agentic AI in organizational security models and risk posture.
read more →

Microsoft Security: New Agent 365 and Defender Integrations

🔒 Microsoft previewed new Microsoft Defender capabilities within the Agent 365 tooling gateway to give security teams near real-time visibility and control over agentic workflows, using webhook-based evaluation to detect, block, and investigate anomalous agent actions before execution. Separately, Microsoft Defender for Cloud now integrates with GitHub Advanced Security generally available to map code changes to production, prioritize alerts using runtime context, and enable coordinated remediation. A hands-on Microsoft Purview demo demonstrates AI-powered data security investigations across the data estate.
read more →

Agents Can Now Provision Cloudflare via Stripe Integration

🤖 Agents can now provision Cloudflare resources and complete billing through Stripe Projects, enabling end-to-end deployment without manual dashboard steps. Using a co-designed protocol, an agent can discover available services, create or link a Cloudflare account, and receive API credentials to deploy code and register domains. Stripe supplies a payment token (not raw card data) with a default $100/month cap, and human approval can be requested when needed. Any platform with signed-in users can adopt the same orchestration flow.
read more →

Securing and Governing AI Agents Through an AI Gateway

🔒 Palo Alto Networks announced its intent to acquire Portkey and integrate Portkey’s AI Gateway into Prisma AIRS to provide a centralized control plane for agentic AI. The combined platform will offer a unified API to thousands of LLMs, an agent registry, semantic routing, caching and runtime protections such as Agent Artifact scanning and automated red teaming. Integration with CyberArk is intended to enforce agent identity and least‑privilege controls. The goal is to enable enterprises to move autonomous workloads from development to production with consistent governance and minimal performance tradeoffs.
read more →

Google-managed MCP Servers Now Available Across Google Cloud

🔌 At Google Cloud Next ’26, Google announced that more than 50 Google-managed MCP servers are generally available or in preview, enabling AI agents to connect securely to Google and Google Cloud services without local MCP deployments. The managed endpoints integrate with major agent runtimes and frameworks including Gemini CLI, LangChain, ADK, and others, supporting Resources and Prompts as protocol primitives in addition to Tools. The offering emphasizes enterprise-grade security, governance, and observability through native IAM controls, Model Armor content safety, OpenTelemetry tracing, and Cloud Audit Logs.
read more →

Amazon Quick Desktop Preview for macOS and Windows

🖥️ Amazon Quick is now available as a native desktop preview for macOS and Windows, extending the assistant beyond the browser to leverage local files, OS-level notifications, and native desktop controls. The desktop app can read and work with files on the machine without uploading them, surface action-item, calendar, and message alerts, and automate both browser-based and desktop workflows. Memory, knowledge graph, and agents are shared with the web experience, and the preview supports local Model Context Protocol (MCP) connections for coding agents.
read more →

AI as Manager: Elevating the SOC Tier 1 Analyst Role

🤖 AI agents are shifting the Tier 1 SOC analyst role from manual triage to oversight and decision-making. Instead of spending hours pivoting across logs and telemetry, analysts can delegate evidence collection to agentic AI that queries systems, correlates signals and builds evidence chains in real time. The human role becomes orchestration—reviewing outcomes, validating uncertainty and aligning actions with business risk. Trust is earned via transparency, staged deployments and practitioner-led adoption.
read more →

Autonomous AI Agents Create a New Enterprise Attack Surface

🔒Attackers are increasingly hijacking legitimate AI agents and compromised credentials to extract sensitive information, turning in-house assistants into active threats. These agents become 'agentic endpoints'—autonomous identities with broad privileges that often evade traditional controls by using plugins, extensions, and stolen API tokens. Organizations need a consolidated security platform, continuous verification through PAM and Zero Trust, and board-level governance to manage this accelerated, AI-driven risk.
read more →

Bridging the AI Agent Authority Gap with Observability

🔒 The contributor reframes AI agents as delegated identities rather than independent actors, arguing enterprises cannot safely govern agents without first governing the identities that delegate authority to them. It calls out pervasive "identity dark matter"—unmanaged human and machine credentials that create hidden permissions and execution paths which agents can amplify. The piece recommends sequencing remediation: first illuminate and reduce identity dark matter across humans, bots, and service accounts, then feed continuous telemetry into a real‑time delegation authority engine. Orchid's continuous observability model is presented as that live feed, enabling dynamic decisions to allow, recommend, constrain, or block agent actions based on delegator posture, intent, application context, and scope.
read more →

AWS for SAP MCP Server Now GA on Amazon Bedrock AgentCore

🔒 AWS has announced general availability of the AWS for SAP MCP Server on Amazon Bedrock AgentCore, enabling AI agents to connect directly and securely to SAP ERP systems at scale. Built on Model Context Protocol (MCP) and SAP OData standards, the server supports CRUD access to sales orders, purchase orders, materials, and finance documents. The managed AgentCore Runtime provides session isolation, private connectivity, and dual-layer authentication with CloudWatch telemetry and CloudFormation templates for rapid, no-infrastructure deployment.
read more →

Google Cloud Next Day 2: Gemini Enterprise Agent Platform

🤖 At Google Cloud Next day 2, the developer keynote focused on the Gemini Enterprise Agent Platform, demonstrating tools to build, simulate, evaluate, and scale autonomous agents. Presentations covered the Agent Development Kit (ADK), Model Context Protocol (MCP) servers, Agent Runtime, Memory Bank, Agent Registry, A2UI/A2A standards, and debugging with Gemini Cloud Assist. Speakers also addressed security and governance with Agent Identity, Agent Gateway, and partner demos from Wiz, and released source code and codelabs to help teams adopt agentic development.
read more →

Google pushes agentic AI defenses to protect cloud systems

🛡️ Google unveiled a suite of agentic AI defenses at Google Cloud Next '26 to help SOC teams manage a surge of vulnerabilities tied to Anthropic Mythos. The launch includes three new agents in Google Security Operations — threat hunting, detection engineering, and third-party context — plus expanded Wiz integrations and an AI-BOM to inventory AI components. Additional controls like Agent Identity, Agent Gateway, and Model Armor aim to govern the emerging 'agentic web' and mitigate prompt injection, data leakage, and shadow AI risks.
read more →

Google shifts to agentic defenses after Mythos reveal

🔐 Google announced a shift to agent-centric security at Google Cloud Next '26, positioning AI agents to help SOC teams respond to the potential surge of vulnerabilities tied to Anthropic's Mythos. It introduced three new agents in Google Security Operations — a threat hunting agent, a detection engineering agent and a third-party context agent — and said its existing triage agent has processed over five million alerts, reducing analysis from about 30 minutes to roughly a minute with Gemini. Additional moves include expanded Wiz integrations, an AI-BOM to inventory AI components, agentic automation features, Model Armor protections, Agent Identity and Agent Gateway controls, and modern IAM simplifications to streamline permissions.
read more →