< ciso
brief />
Tag Banner

All news with #agentic ai tag

726 articles · page 20 of 37

Addressing the OWASP Top 10 Risks in Agentic AI with Copilot

🔐 This post summarizes the OWASP Top 10 for Agentic Applications (2026) and explains how Microsoft applies practical mitigations using Copilot Studio and Agent 365. It highlights that agentic systems merge application, identity, and data risk and can act autonomously across workflows, amplifying the consequences of failures. The article lists ten failure modes — including goal hijack, tool misuse, identity abuse, memory poisoning, and rogue agents — and outlines development and operational controls such as containment, scoped permissions, observability, and lifecycle governance to reduce exploitation and cascading impact.
read more →

APIs Are the New Perimeter: How Security Leaders Secure Them

🔒 APIs are increasingly the enterprise perimeter, and recent breaches show traditional protections often miss API-layer abuse. Security teams report attacks that exploit business logic or use stolen credentials, which EDR and WAF tools can treat as legitimate traffic. CISOs are adopting API governance, centralized inventories, identity-aware access controls, and API gateways integrated into CI/CD to enforce least-privilege and reduce misconfiguration risk. As agentic AI and automated agents proliferate, stronger token handling, credential rotation, and real-time behavioral monitoring are becoming essential.
read more →

Agentic GRC Teams Have the Tech — Mindset Is Missing

🤖 Enterprise GRC teams often have the technical capability to deploy agentic AI but stall over a deeper concern: identity and role. Agents can replace operational tasks—evidence gathering, control testing, remediation tracking—but they still require human-defined logic for risk appetite, remediation criteria, and context. Anecdotes builds agentic GRC that automates operations while relying on practitioner judgment. The outcome is an opportunity for practitioners to reclaim time to focus on true risk management rather than program maintenance.
read more →

RSAC 2026 Wrap-Up: AI Agents and Security Trends Overview

🎥 RSAC 2026 concluded with AI agents taking center stage across sessions and discussions. ESET Chief Security Evangelist Tony Anscombe, on the ground for the conference, highlights that AI was discussed both as a strong defensive capability and, more urgently, as a growing risk many organizations have not yet fully addressed. Watch the video for concise, practical takeaways from the event, where ESET delivered a record six presentations.
read more →

Securing Agentic AI in Financial Services: Observability

🔒 This post explains how financial institutions should augment traditional security frameworks with AI-specific controls when deploying agentic AI. It emphasizes two foundational capabilities—comprehensive observability of agent workflows and fine-grained tool access controls—to preserve explainability and accountability. The author presents seven design principles and actionable implementation guidance, referencing SR 11-7 and practical AWS tooling such as Amazon Bedrock AgentCore and monitoring integrations.
read more →

AI Named Top Cybersecurity Priority as Threats Rise

🔒 A PwC report finds AI is now the top cybersecurity investment priority for defenders as criminals rapidly weaponize generative models. The firm's Annual Threat Dynamics 2026 study warns adversaries are using AI to accelerate malware development, automate reconnaissance and scale social engineering, including via dark‑web LLMs. PwC cites agentic tools like ReaperAI being repurposed in real campaigns, but also stresses that AI can empower defenders with faster detection, automated containment and intelligence‑led decision‑making when embedded into security strategies.
read more →

Agent Plugin for AWS Serverless Accelerates AI Dev Workflows

📦 AWS introduces the Agent Plugin for AWS Serverless, which integrates AI coding assistants like Kiro, Claude Code, and Cursor to simplify building, deploying, troubleshooting, and managing serverless applications. The plugin packages reusable agent skills, sub-agents, hooks, and MCP servers to provide contextual guidance across the development lifecycle. It supports Lambda integrations with common event sources, IaC workflows via SAM and CDK, long‑running stateful patterns with durable functions, and API design with API Gateway. Skills are distributed in the open Agent Skills format and are available in AI tooling that supports agent plugins or skills.
read more →

AI Agents Invalidate the Traditional Cyber Kill Chain

⚠️ AI agents embedded across SaaS environments can render the traditional kill chain ineffective when they are compromised. The piece cites a September 2025 Anthropic disclosure where a state-backed actor used an AI coding agent to perform autonomous espionage, handling the majority of tactical operations. Because agents already hold broad permissions and move data as part of normal workflows, a breach looks like legitimate activity. Reco is positioned as a solution to discover agents, map blast radius, enforce least privilege, and detect anomalous agent behavior in real time.
read more →

Charlotte AI AgentWorks: Agentic SOAR for Modern SOCs

🔐 CrowdStrike introduces Charlotte AI AgentWorks and Charlotte Agentic SOAR to enable agentic security operations that orchestrate context-aware agent fleets and automate responses at machine speed. The platform integrates frontier models from Anthropic, NVIDIA and OpenAI and leverages Falcon telemetry, threat intelligence, and industry partners to keep agents context-aware and secure. Built-in guardrails preserve human oversight and governed autonomy while mission-ready agents handle tasks from triage to malware analysis. Customers report sharply reduced manual workloads, restored analyst capacity, and improved decision accuracy.
read more →

Governing AI Agent Behavior Across Intent Layers Guide

🧭 This article presents a practical framework for governing AI agents by aligning user, developer, role-based, and organizational intent. It prescribes a precedence model—organization, role, developer, then user—to resolve conflicts and preserve security and compliance. The authors illustrate expected agent behaviors (refuse, escalate, clarify, or proceed) and advocate for guardrails, least-privilege access, continuous evaluation, telemetry, and human-in-the-loop controls to sustain safe, reliable agent operations.
read more →

Gartner Market Guide Marks Emergence of Guardian Agents

🔒 Gartner's inaugural Market Guide for Guardian Agents defines a new enterprise control layer that supervises AI agents to keep their actions aligned with organizational goals and boundaries. The article stresses risks from unmanaged non-human identities—so-called identity dark matter—and lists mandatory capabilities across visibility, continuous assurance, and runtime enforcement. It urges enterprises to adopt an enterprise-owned guardian layer rather than relying solely on platform-native controls.
read more →

Autonomous AI Adoption Is Rising — Benefits and Risks

🤖 Early this year, enterprises began experimenting with autonomous, agentic tools such as Anthropic’s Claude Cowork and the open-source OpenClaw, which can access apps, files and the web to execute multi-step workflows on users’ behalf. Proponents highlight large efficiency gains and the ability to offload routine IT tasks to non-technical staff, while security researchers warn of misalignment, prompt‑injection flaws and unintended destructive actions. IT leaders are advised to permit controlled experimentation, enforce strict permissions and monitoring, and invest in clean operational context to reduce amplified mistakes and limit shadow‑AI risk.
read more →

Microsoft Open Source and AKS at KubeCon Europe 2026

🚀 At KubeCon + CloudNativeCon Europe 2026, Microsoft outlined coordinated open-source and AKS enhancements designed to bring AI workloads to Kubernetes with enterprise-grade operational patterns. Upstream work includes DRA reaching GA, Workload Aware Scheduling for Kubernetes 1.36, DRANet Azure RDMA compatibility, and new projects such as AI Runway, HolmesGPT (CNCF Sandbox), and Dalec. AKS platform updates add identity-aware networking with Azure Kubernetes Application Network, meshless Istio routing, WireGuard and Cilium-based encryption, built-in GPU telemetry into managed Prometheus/Grafana, per-flow L3/L4 and L7 observability, a managed Cilium cluster mesh via Fleet Manager, Elastic SAN shared storage, AKS Desktop GA, and safer upgrades with blue-green agent pool upgrades and agent pool rollback.
read more →

RSAC '26: Supercharging Agentic AI Defense with Threat Intel

🔒 Google Cloud outlined a coordinated set of AI-driven security advances at RSAC ’26, anchored by the completed acquisition of Wiz and new agentic defense capabilities. The company highlighted Mandiant's M-Trends 2026 findings on rapid adversary operations and published guidance on AI risk and resilience. Previewed offerings include Google Security Operations with autonomous triage agents, dark web intelligence powered by Gemini, and expanded protections across model, data, and network security.
read more →

Agentic Commerce Risks: AI-Enabled Retail Fraud Scenarios

🔐At the NRF Big Show in January 2026, Google introduced the Universal Commerce Protocol (UCP) and highlighted compatibility with the Agent Payments Protocol (AP2), promising tokenized payments and verifiable credentials. Unit 42 warns that indirect prompt injection—where agents ingest hidden instructions while browsing—can enable novel fraud such as gift card payload poisoning and refund logic hijacking. Industry forecasts (Bain, McKinsey) predict substantial agentic commerce adoption, increasing the attack surface. Recommended mitigations include protocol guardrails (AP2), Know Your Agent, agent reputation scoring, Unit 42 AI Security Assessments and Prisma AIRS.
read more →

Amazon Bedrock AgentCore Runtime Adds WebRTC Support

🔊 Amazon Bedrock AgentCore Runtime now supports WebRTC for low-latency, bidirectional streaming between clients and agents, enabling real-time audio and video in browser and mobile applications. WebRTC complements existing WebSocket support by providing peer-to-peer, UDP-based media transport optimized for voice agents and other media-intensive experiences. AgentCore Runtime supports managed TURN via Amazon Kinesis Video Streams, third-party providers, or self-hosted TURN, and the capability is available in 14 AWS Regions.
read more →

CTI-REALM: Benchmark for End-to-End Detection Rules

🔍 Microsoft introduces CTI-REALM, an open-source benchmark that evaluates AI agents on end-to-end detection engineering by turning real-world cyber threat intelligence into validated detections. The benchmark places agents in realistic, tool-rich environments where they must read CTI reports, explore telemetry, iterate on KQL queries, and produce Sigma rules and KQL-based logic scored against ground truth across Linux, AKS, and Azure. CTI-REALM's checkpoint-based scoring surfaces whether failures arise from CTI comprehension, technique mapping, data-source selection, or query construction, helping teams decide where human oversight and guardrails are required.
read more →

Amazon Polly adds 10 voices, regions, and streaming

🔊 Amazon Web Services announced general availability of 10 new highly expressive Generative voices in Amazon Polly, covering eight locales including American, British, New Zealand, and Singapore English, plus French, Italian, German, and Swiss German. The Generative engine is now hosted in two additional regions — Europe (London) and Canada (Central) — and introduces a Bidirectional Streaming API. The new streaming capability lets customers send text and receive synthesized audio simultaneously, simplifying low-latency integrations with LLM-based systems for chatbots, game characters, and other real-time speech applications.
read more →

Securing Agentic AI: End-to-End Enterprise Protections

🔒 Microsoft presents an end-to-end strategy to secure agentic AI with the new Agent 365 control plane and updates across Microsoft Defender, Entra, Purview, and Sentinel. Announced for RSAC 2026, these measures focus on visibility, continuous identity protection, data loss prevention for Copilot prompts, and prompt-injection defenses to help organizations observe, govern, and defend agent ecosystems at scale.
read more →

AWS MCP Server (Preview) adds monitoring and semantic search

📈 The AWS MCP Server (Preview) now publishes operational metrics to Amazon CloudWatch and adds semantic similarity search for Agent SOP discovery. Metric publishing under the AWS-MCP namespace tracks invocation counts, success rates, client and server errors, and throttling for tools such as call_aws and retrieve_agent_sop, enabling alarms and visibility into agent-driven activity. The documentation search (search_documentation) now returns relevant Agent SOPs alongside AWS docs, helping AI assistants find the correct workflows.
read more →