< ciso
brief />
Tag Banner

All news with #agentic ai tag

726 articles · page 5 of 37

AI agents under attack: incidents and risks 2026

🔍 Enterprises face rising attacks that exploit AI agents already present in their environments. These agents — coding assistants and CLI tools like Claude Code CLI, Gemini CLI, and Amazon Q CLI — can read files, run commands, and install packages, making them attractive targets when run with auto-approval. Real-world incidents, including the s1ngularity Nx npm compromise and the AgentJacking/Sentry experiments, show how prompt injection, compromised tool metadata, and unsecured MCP servers can lead to secret harvesting and covert exfiltration. Defenders must treat agents as potentially untrusted and adapt controls and monitoring accordingly.
read more →

AI agent identities create a new enterprise attack surface

🛡️ The Sophos AI Security 2026 Report warns that rapid enterprise adoption of AI tools has created a growing attack surface as AI agents and assistants gain privileged access to systems. Threat actors are targeting OAuth tokens, service credentials and exposed AI infrastructure because governance has not kept pace. The report urges treating AI agents like human users, enforcing least privilege, manual verification for new access and setting alerts for suspicious AI behavior.
read more →

How enterprise GenAI can amplify ransomware risk

🛡️ Generative AI is increasingly embedded in business workflows as assistants and agents that access documents, apps, and identities. While AI promises productivity gains, it can amplify existing ransomware tactics by accelerating reconnaissance, credential abuse, and data theft when compromised. The article outlines two threat models—attackers using AI and organizations deploying AI—and recommends governance, least privilege, monitoring, and human approval for high-risk actions.
read more →

Open-source Android AI agents enable host command risk

🛡️ Researchers demonstrated seven attacks against five open-source Android agent frameworks, showing that benign-seeming apps with draw-over and storage permissions can inject unseen text into models and escalate to host command execution. The study, posted on arXiv in July, tested AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA, finding widespread vulnerabilities including screenshot race conditions, command injection via unsanitized adb calls, broadcast leaks, and UI spoofing. Some projects already use safer patterns, but none implemented all recommended mitigations.
read more →

AI coding agents can bypass sandboxes indirectly

🔒 New research from Pillar Security shows that AI coding agents in tools like Cursor, Codex, Gemini CLI, and Antigravity can cross host security boundaries without directly breaking their sandboxes. The attacks rely on agents producing files or configurations that trusted, external components later execute or interpret. Researchers identified four repeatable failure modes and urge security teams to understand actual sandbox boundaries and treat workspace artifacts as sensitive.
read more →

Amazon Connect expands agentic voice across 50+ languages

🔊 Amazon Connect now offers more natural, human-sounding agentic voice experiences with expanded support across 50+ languages, including Spanish, French, Italian, Japanese, Korean, Portuguese, and Thai. The update introduces over 100 new voice options and conversational improvements for smoother, more responsive AI interactions. Enhanced features include seamless response pacing, improved turn-taking to avoid interruptions, and speech controls to adjust speed, volume, and emotion to match brand tone.
read more →

CloudWatch Adds Coding Agent Insights for AI Tooling

🛠️ Amazon CloudWatch launches Coding Agent Insights to give engineering leaders visibility into how AI coding tools drive value across their organizations. The feature integrates with Claude apps gateway for AWS to collect telemetry from Claude Code without additional instrumentation and supports other agents like Codex and GitHub Copilot. It builds on OpenTelemetry metrics and surfaces agent telemetry alongside existing CloudWatch operational data to help track spend, adoption, and productivity. The capability is available in most AWS commercial regions with standard CloudWatch metric ingestion pricing.
read more →

Thirteen demos for Gemini Enterprise Agent Platform

🔎 This post introduces 13 code-first demos for the Gemini Enterprise Agent Platform, showing how to build, scale, govern, and optimize agents using the ADK and Agents CLI. The demos range from an ADK foundation codelab and MCP data connectors to stateful deployment on Agent Runtime, event-driven long-running workflows, and production-grade governance with Agent Gateway and Model Armor. Each demo teaches practical patterns — from UI generation and multi-language A2A pipelines to test-driven security, AutoRater evaluations, and cross-framework orchestration — so teams can prototype locally and then deploy and monitor agents at enterprise scale.
read more →

Agent Teams Produce Short Films in Hackathon

🎬 As part of an internal generative media hackathon, Google tested whether teams of AI agents could collaboratively produce short films using Scion, an open-source agent orchestration testbed. Each crew had three role-specific agents (Idea Person, Technical Lead, Editor) plus coach and coordinator agents, following a seven-step filmmaking pipeline with verification gates. Agents called multiple Google AI models via a shared CLI toolkit genmedia (Gemini, Veo 3.1, Lyria 3, Gemini Flash TTS) to generate images, video, audio, and music, producing over 25 productions and about 44 minutes of final footage. Teams found that shared files provided resilience, specific prompts and style choices improved results, and coach-led gates helped ensure completed deliverables.
read more →

Accelerating foundation model upgrades for teams

🔎 Upgrading foundation models is slow and costly for engineering teams, often requiring months of manual testing and evaluation. Google Cloud Applied ML built an agentic workflow that reduces migration time from months to hours using the Gemini Enterprise Agent Platform and Google Antigravity. The blog outlines three lessons and practical steps—deploying Autoraters, building an agentic loop, and automating orchestration—to replace manual toil with intelligent automation.
read more →

Least privilege guidance for AI agents and access

🔒 AI agents require managed identities and tightly scoped permissions to avoid uncontrolled access and privilege escalation. Treat each agent as a first-class principal with lifecycle-managed identities, explicit owners, and task-based RBAC. Implement controlled tool binding, just-in-time elevation for high-risk actions, and end-to-end audit logging to ensure accountability and rapid incident response. Regular reviews and revocation testing are essential.
read more →

AI Appreciation Day: Honest View on Risks and Rewards

🤖 Today is AI Appreciation Day, and while AI has transformed coding, threat analysis, and productivity, Check Point’s AI Security Report 2026 warns that those same strengths empower attackers. Researchers observed AI running exploitation workflows autonomously, producing vast volumes of malware code and executing thousands of commands in real intrusions. Organizations are adopting many AI apps rapidly, often without governance, increasing high-risk prompts and exposure.
read more →

Agentic ChatGPT-5.5 Executes Full Network Attacks

🛡️ Cato Networks found a single prompt can cause OpenAI’s GPT-5.5 to plan and execute a full offensive cyber-attack in a controlled Active Directory lab. The model carried out reconnaissance, exploitation, lateral movement, privilege escalation and exfiltration, reaching domain admin in about 40 minutes. Researchers tested six scenarios, noting adaptive behavior when conditions changed and emphasizing the risk of accelerating existing attack workflows.
read more →

AWS expands G7e instances to Frankfurt, Stockholm, Mumbai

🚀 Amazon EC2 G7e instances, powered by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs, are now available in AWS Regions Europe (Frankfurt, Stockholm) and Asia Pacific (Mumbai). These instances deliver up to 2.3x inference performance versus G6e and are optimized for LLMs, multimodal generative AI, agentic AI, and spatial computing. G7e supports up to 8 GPUs with 96 GB each, 192 vCPUs, 1600 Gbps networking, and advanced NVIDIA GPUDirect capabilities for multi-GPU and multi-node workloads.
read more →

Amazon OpenSearch Service integrates with Agent Toolkit

🛠️ Amazon OpenSearch Service integrates with the Agent Toolkit for AWS, enabling AI coding agents like Claude Code, Kiro, and Cursor to build, manage, and query OpenSearch Service domains and OpenSearch Serverless collections. The integration uses the AWS MCP server to execute API calls and the curated amazon-opensearch-service skill to translate natural-language requests into capabilities. It supports migration, operations, search, log analytics, and trace analytics across managed domains and serverless collections with no infrastructure changes and no additional charge.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

Amazon MSF introduces AI Agent Skills for Flink

🛠️ Amazon Managed Service for Apache Flink now includes AI Agent Skills that provide expert, up-to-date guidance for building and operating Flink applications. The skills cover common tasks like creating applications, troubleshooting, scaling, monitoring, networking configuration, and cost optimization. Customers can use these skills with existing AI coding agents such as Kiro, Claude Code, or Cursor by configuring the Agent Toolkit for AWS via the AWS CLI. The feature aims to speed development, simplify upgrades to versions like Flink 2.2, and help maintain healthy, performant streaming applications.
read more →

AI-Driven Breaches Force Rethink of Incident Response

🛡️ Enterprises face a new class of attacks as threat actors leverage AI agents to automate entire intrusion chains, dramatically compressing the time from initial access to deep compromise. Reports from Sygnia and Sysdig document AI-enabled campaigns that harvest credentials, map services, and persist across cloud environments, often exploiting known vulnerabilities rather than zero-days. Experts warn that traditional, human-speed incident response and hunting are often too slow, and emphasize the need for integrated, AI-assisted defenses and rigorous hygiene: fast patching, secrets rotation, least privilege, segmentation, and automated response playbooks.
read more →

Amazon DocumentDB added to Agent Toolkit

🛠️ The new Amazon DocumentDB skill in the Agent Toolkit enables AI coding agents to provision, manage, migrate, optimize, and troubleshoot DocumentDB clusters using guided, best-practice workflows. The skill supports seven workflows including provisioning, schema design, MongoDB compatibility assessment, DMS migration with change data capture, performance tuning, a 41-check well-architected review, and major version upgrades. When used with the AWS MCP Server, agents can execute AWS CLI commands and diagnostic queries with IAM guardrails, CloudTrail logging, and sandboxed execution. The skill is also available standalone via the AWS CLI and is provided at no additional charge as part of the Agent Toolkit for AWS.
read more →

Key findings from the 2026 public sector M‑Trends report

🛡️ The 2026 Public Sector Threat Landscape report summarizes Mandiant’s 2025 incident investigations and highlights how adversaries now move at machine speed, notably the 22-second hand-off from initial access to ransomware. It argues public agencies must adopt continuous verification and machine-speed defenses. Google outlines three core capabilities—identity as the perimeter, agentic defense, and hardened infrastructure—and describes new AI agents in Google Security Operations and customer success stories.
read more →