< ciso
brief />
Tag Banner

All news with #agentic ai tag

850 articles · page 17 of 43

OWASP Agentic AI Security Maturity Model Released

🛡️ The Open Worldwide Application Security Project (OWASP) published a new agentic AI security maturity framework in the GenAI Security Project paper "State of Agentic AI Security and Governance" on June 3, and introduced it at Infosecurity Europe 2026 on June 4. The Enterprise Adoption Maturity Model maps deployments (from shadow AI to multi-agent systems) against governance maturity (from ad hoc to continuous oversight). It provides a decision tool to identify mismatches and prescribes either tailored controls for agentic systems or constrained agent permissions until governance catches up.
read more →

Embed security within agentic AI coding tools

🔒 Ox Security urges that appsec be integrated directly into AI coding tools as agentic development accelerates code changes beyond traditional pipelines. Speaking at Infosecurity Europe, field CTO Boaz Barzel argued that security must become a continuous, contextual property of creation rather than a bolt-on stage. He outlined four agentic attack surfaces—input, tools, execution and output—and advocated autonomous security agents that pentest and validate every commit to reduce MTTR and achieve full coverage.
read more →

AWS MCP Server Adds Cross-Account Cross-Role Access

🚀 Today AWS introduced cross-account and cross-role access for the AWS Model Context Protocol (MCP) Server, part of the Agent Toolkit for AWS. This update lets AI coding agents such as Kiro, Claude Code, or Codex operate across multiple AWS accounts and IAM roles within a single session without restarts. Previously, changing accounts required stopping the session, updating local credentials, and restarting the MCP server; now agents can specify a profile per command. The feature is intended to streamline multi-account workflows and reduce context-switch friction. The MCP Server is available in US East (N. Virginia) and Europe (Frankfurt).
read more →

Updated Taxonomy of Agentic AI Failure Modes

🔎 The Microsoft AI Red Team released a v2.0 update to the Taxonomy of Failure Modes in Agentic AI Systems, grounded in twelve months of red team engagements and operational data. The revision adds seven new failure mode categories—such as agentic supply chain compromise, goal hijacking, and visual attacks against computer-use agents—expands mitigations, and emphasizes supply chain, zero‑trust, and session hardening.
read more →

AI and Evasion Force Rethink of Network Prevention

🔍 For years network security relied on content inspection and static threat intelligence, but the rise of agentic AI and evasive techniques has upended that model. Unit 42 research shows attackers exploit the IP layer and use anonymizers, rapid infrastructure rotation, and AI-enabled stealth to bypass legacy controls. Security strategies must augment deep inspection with real-time IP-layer monitoring and continuous verification to defend at machine speed.
read more →

Deploy ADK agents on GKE Autopilot securely

🚀 This tutorial shows how to build an AI agent with Google’s Agent Development Kit (ADK), containerize it, and deploy it to GKE Autopilot using Vertex AI (Gemini) as the model backend. It walks through local testing, creating a multi-stage Docker image, pushing to Artifact Registry, and configuring a Kubernetes Deployment and Service. The guide emphasizes secure authentication with Workload Identity and exposes the agent via the Kubernetes Gateway API with a Google-managed TLS certificate.
read more →

ECS Managed Instances Add Trainium and Inferentia

🚀 Amazon ECS Managed Instances now supports AWS Trainium and AWS Inferentia accelerators, enabling scalable training and inference for generative AI workloads. This fully managed compute option offloads infrastructure operations to AWS while preserving the full capabilities of Amazon EC2. You can select Inferentia2, Trainium1, or Trainium2 when creating a capacity provider and set NEURON_CORE=all to allocate the accelerator per task. Management charges apply in addition to standard EC2 costs.
read more →

SageMaker AI adds multi‑turn reinforcement learning

🧭 Amazon SageMaker AI introduces multi-turn reinforcement learning (RL), a serverless model customization method for fine-tuning models on multi-step, agentic tasks. The feature trains models against users' agent environments, rewarding entire decision sequences to improve task accuracy of smaller, cost‑effective models versus larger general-purpose models. It integrates with Amazon Bedrock AgentCore Runtime and other deployment targets, and handles rollout orchestration, trajectory collection, training, and checkpoints, with MLflow tracking and evaluation metrics. Multi-turn RL runs serverlessly and is available in SageMaker Studio and the SageMaker Python SDK, supporting several foundation models in specific regions.
read more →

Microsoft unveils containment for agentic AI security

🔒 Microsoft announced new controls to contain agentic AI workloads, including the Microsoft Execution Container (MXC) runtime and enhancements to the multi-agent vulnerability research system MDASH. MXC is a policy-driven sandbox for specifying and enforcing access to files, networks, credentials, and resources at runtime across Windows, Linux, and macOS. The company also highlighted Agent 365 SDK, Windows 365 for Agents, and two open-source standards—ASSERT and Agent Control Specifications—to govern agent behavior across platforms.
read more →

AI-driven urgency reshapes enterprise cybersecurity budgets

🔒 The rapid rise of frontier and agentic AI is creating board-level urgency that may finally unlock sustained cybersecurity funding. Industry leaders at recent conferences noted that autonomous AI systems expose operational risk, widen attack surfaces, and outpace traditional security architectures. CISOs are reframing cybersecurity as an operational enabler for safe AI adoption, pushing for investments in visibility, identity, monitoring, and AI-specific controls. Vendors and experts caution that budget requests need clear business cases tied to measurable outcomes.
read more →

Building an Agentic Enterprise System for AI

🧭 Microsoft outlines a shift from isolated AI tools to a unified, enterprise-grade agent platform that runs real work. The post emphasizes a single integrated system spanning Azure, GitHub, Microsoft IQ, Foundry, Agent 365, and Microsoft 365 to build, contextualize, run, govern, and improve agents. It stresses secure-by-design governance, model choice, continuous improvement through feedback and tuning, and production-grade runtimes. The approach centers developers and enterprise context to make agents trustworthy and scalable.
read more →

Accelerating AI agents with GCS MCP servers

🚀 Google Cloud Storage (GCS) is positioned as the preferred home for large-scale unstructured data and as a foundational component for production AI agents. This post highlights customer examples—Palo Alto Networks and Snap—using GCS as agent memory and analytics storage, and explains how the Model Context Protocol (MCP) enables secure, standardized access. Google offers two MCP server options: a fully managed Remote MCP server for easy, scalable deployments, and a self-managed Local MCP server for custom tooling and transformations, both integrated with Google Cloud security, observability, and tooling.
read more →

Microsoft Build 2026: Agentic Apps with Fabric

🧭 Microsoft highlights how AI-driven agentic workflows demand a shared data context. Microsoft Fabric is presented as a unified data and AI platform that enables developers and agents to build production-ready apps by providing consistent organizational context. New announcements include the open-source Rayfin SDK/CLI for rapid backend deployment and Azure HorizonDB (PostgreSQL-compatible) in public preview, optimized for AI workloads.
read more →

Bayer overhauls security awareness for AI era

🧭 At Infosecurity Europe 2026, Bayer CISO Kevin Jones outlined a shift from checklist-based guidance to psychology-first security awareness to counter AI-enabled social engineering. The firm mandates behavior-focused training, ties AI access to role-based modules, and gates agent development behind completion. Bayer is moving SOCs toward supervised automation and updating supplier contracts and governance to enforce AI transparency and controls.
read more →

Amazon Quick adds VPC support for MCP servers

🔒 Amazon Quick now supports connecting privately hosted Model Context Protocol (MCP) servers via Amazon Virtual Private Cloud (VPC). This enables organizations to integrate proprietary MCP servers running on Amazon EC2, AWS Fargate, AWS Agentcore, or other private compute without exposing them to the public internet. During connector creation, choose your VPC and provide your MCP server URL so teams can interact with private MCPs in Quick while traffic remains routed securely through the VPC.
read more →

OpenAI GPT-5.5, GPT-5.4 and Codex now on Bedrock

🚀 Amazon Bedrock now supports OpenAI GPT-5.5, GPT-5.4, and Codex for production use, offering the same AWS security, governance, and operational controls. GPT-5.5 delivers advanced capabilities for agentic coding, data analysis, and multi-step autonomous tasks on a next-generation inference engine. Codex is available via a dedicated App, CLI, and IDE integrations for Visual Studio Code, JetBrains, and Xcode, and can be configured to run through Bedrock with pricing aligned to OpenAI first-party rates.
read more →

OWASP launches Agentic Research Council for AI risks

🧭 At Infosecurity Europe 2026, OWASP will unveil the Agentic Research Council to better align fast‑moving agentic AI capabilities with security research and operational practice. Launched from the GenAI Security Project’s Agentic Security Initiative, the council will prioritize a public research pipeline, convene working groups and connect academic outputs to deployable mitigations. The initiative aims to accelerate runtime‑focused defenses against multi‑agent threats.
read more →

Palo Alto Networks Unifies AI Gateway for Agents

🔒 Palo Alto Networks has completed its acquisition of Portkey and will integrate Portkey’s AI Gateway into Prisma AIRS to provide a centralized control plane that secures and governs AI agents at scale. The integrated Prisma AIRS AI Gateway will offer unified APIs, an agent registry, semantic routing, artifact scanning, automated red teaming and runtime security to identify, authenticate and authorize agent interactions in real time. This aims to give enterprises a single enforcement point to manage agent identity, least-privilege access and consistent policies across autonomous workloads.
read more →

How Google SRE Uses Agentic AI to Improve Operations

🤖 Google SRE describes how agentic AI augments traditional Site Reliability Engineering across the software lifecycle, from design and deployment to incident response and postmortems. The team applies AI agents for anomaly detection, playbook maintenance, alert enrichment, and automated mitigation while enforcing strong controls for security, explainability, and business continuity. Their approach pairs Gemini-based models and internal platforms with existing observability and governance practices.
read more →

AWS announces next-generation OpenSearch Serverless GA

🚀 The next generation of Amazon OpenSearch Serverless is now generally available, offering a fully managed search and vector engine optimized for agentic workflows. It auto-scales up to 20x faster and provisions resources in seconds, supports scale-to-zero and pay-per-usage pricing, and can reduce costs by up to 60% versus provisioning clusters for peak loads. New features include a shared storage layer that decouples compute and storage, two resource-based endpoints for simplified network connectivity, and native integrations with AI development platforms and OpenSearch Agent Skills.
read more →