< ciso
brief />
Tag Banner

All news with #agentic ai tag

726 articles · page 6 of 37

Why the AI Agent Harness Determines Reliability

🛡️ AI agents leverage LLMs for reasoning but require a robust harness—skills, tools, and live context—to be reliable in network security. Generic agents trained on broad data hallucinate and fail at scale because they lack production-hardened experience and up-to-date environmental visibility. Check Point emphasizes skills from 30 years of deployments, a real-time Network Knowledge Graph, and contextualized policies to keep agent actions auditable and trustworthy.
read more →

EMR on EKS Adds Spark Troubleshooting Agent

🛠️ Amazon EMR on EKS now integrates an Apache Spark troubleshooting agent that provides automated root cause analysis and PySpark recommendations through natural language, simplifying diagnosis of job failures. The agent inspects Spark History Server data, executor logs, and cluster configs to detect issues like memory errors, data skew, resource contention, and connectivity problems. Accessible via a "Troubleshoot with AI" option in the EMR on EKS console and via MCP with compatible AI coding agents, the feature is read-only, IAM-authenticated, logged in CloudTrail, and available in Regions with SageMaker Unified Studio.
read more →

Measuring agent capability with graded difficulty

🔎 This article from Google Data Cloud explores a rigorous, information‑theoretic approach to evaluating AI data agents by converting binary pass/fail tests into graded difficulty sweeps. The team introduces Discovery Bench and iterative surprisal-based query refinement (iSQR) to generate low/medium/high ambiguity variations of queries, quantify surprisal, and map where agents succeed or fail. The piece highlights how this method reveals cliffs and sweet spots in agent behavior and calls for auditing benchmarks themselves to avoid misleading conclusions.
read more →

Microsoft warns of rising Windows security updates

🛡️ Microsoft says it is deploying AI-driven analysis to uncover more zero-day vulnerabilities across the Windows codebase, warning customers to expect an increased number of security updates. The company described a multi-model agentic scanning harness (MDASH) and a separate prove pipeline to validate findings, aiming to reduce false positives and shorten review windows. Microsoft also plans to update its Secure Development Lifecycle to address AI-enabled attack techniques while retaining human oversight to ensure update quality.
read more →

AWS DMS Schema Conversion Adds AI Agent Automation

🧭 AWS Database Migration Service (DMS) Schema Conversion now integrates AI agent automation via the AWS MCP Server. Agents like Kiro, Claude Code, and Cursor can connect and run migration workflows from IDEs using natural language, performing tasks such as creating projects, browsing source metadata, converting schemas, and exporting results. The dms-schema-conversion skill provides predefined procedures and operational sequencing to guide agents and reduce trial-and-error, and agents can assist with converting stored procedures, functions, and triggers. This capability is available for all existing DMS Schema Conversion engine pairs at no additional charge; regional availability is listed on the Supported AWS Regions page.
read more →

GPT-5.6 Available Now in Microsoft Foundry

🚀 Microsoft announces general availability of GPT-5.6 in Microsoft Foundry, integrating frontier models, production agent runtime, and enterprise controls into a single platform. The release includes Sol, Terra, and Luna model tiers with published pricing, Global and APAC Data Zone deployment options, and developer tooling for GitHub Copilot and VS Code. Foundry emphasizes observability, cost controls, and governance to accelerate production agent adoption.
read more →

Microsoft Foundry expands frontier models and agents

🚀 Microsoft announces general availability updates to Microsoft Foundry, combining frontier models, a production agent runtime, enterprise identity and security controls, and Microsoft 365 distribution into one platform. The release includes GPT-5.6 models across global regions and the new Asia-Pacific Data Zone for regional data processing. Developers can build in GitHub Copilot or VS Code and deploy agents using Foundry toolkits and SDKs.
read more →

AWS Partner Central unveils AI lead prospecting

🤖 AWS Partner Central introduces Partner Lead Prospecting, an AI-powered capability for ACE-eligible AWS Partners to accelerate lead conversion. Building on earlier lead enrichment features, it generates personalized sales plays, call scripts, and email outreach tailored to the customer's industry and each partner's solutions. The feature integrates a partner's portfolio into prospecting content to reduce manual research and drafting. Partner Lead Prospecting is available globally to all ACE-eligible partners via the Leads page or the MCP server.
read more →

AlphaEvolve now generally available on Gemini

🧭 AlphaEvolve, now GA on the Gemini Enterprise Agent Platform, is an agentic code optimization and discovery tool designed to tackle hard algorithmic problems across domains like logistics, semiconductors, genomics, and finance. It follows a four-step workflow — Define, Measure, Optimize, Apply — to move from a baseline algorithm to production-ready optimized code. Early customers report substantial gains in accuracy, performance, and efficiency across production pipelines and HPC workloads.
read more →

UK unveils AI-driven national Cyber Shield

🔒 The UK’s NCSC and DSIT unveiled a blueprint called Cyber Shield to deploy autonomous AI agents that detect and neutralize cyberattacks at machine speed. The plan uses cooperating “red” and “blue” agents to identify weaknesses, detect threats and progressively automate remediation while operating under organizational control. The initiative emphasizes explainable and federated AI, industry partnerships, and a staged rollout beginning with government and critical sectors.
read more →

Six-stage maturity model for non-human identities

🔒 This article examines the risks of agentic AI and non-human identities in enterprise environments, illustrating incidents where LLM-based agents caused outages due to weak identity controls. It argues that existing IAM models are insufficient for agents that act autonomously, and cites industry guidance from Gartner, OWASP, CISA and NIST. The author proposes six minimum requirements and a cumulative six-stage NHI maturity model to ensure defensible production deployments.
read more →

Rise of Malicious AI Agents Threatens Organizations

🤖 ESET analysis shows cybercriminals increasingly use AI agents and chatbots to autonomously plan and execute attacks. Researchers reviewed 900,000 AI skills in public repositories and found tens of thousands of suspicious and thousands of malicious toolsets, expanding the attack surface. These agentic tools can exfiltrate data, execute malware, override instructions, and be repurposed from legitimate utilities into harmful capabilities. ESET urges organizations to enforce policies and caution users about downloading free tools from untrusted sources.
read more →

Agents turned attack vector in code security checks

🔍 Researchers at the AI Now Institute demonstrated a proof-of-concept called "Friendly Fire" where autonomous AI coding agents (Anthropic's Claude Code and OpenAI's Codex) execute an attacker's binary when asked to scan untrusted open-source code. The attack hides a malicious binary alongside benign files and a README that prompts the agent to run a security script; in auto-modes the agents approved and executed it without prompting. The weakness is framed as a workflow/design issue rather than a single vulnerable version, and the researchers recommend never giving command-capable agents unattended access to untrusted code.
read more →

Smashing Security Podcast 475: AI Risks and Privacy Gaps

🎧 This episode of Smashing Security discusses a rash of recent cybersecurity incidents, including a 15-year-old who used a chatbot to cancel nearly 47,000 anime subscriptions and the first documented agentic ransomware, JadePuffer. The hosts also examine Apple’s problematic Hide My Email feature, which has been known to leak addresses for over a year. Guest Zoë Rose joins Graham Cluley to assess implications for security and privacy.
read more →

Microsoft details SFI AI system to harden cloud

🚀 Microsoft describes a multi-agent AI system within the Secure Future Initiative (SFI) that continuously evaluates and hardens its cloud services. The system combines code, configuration, identity, network, and runtime evidence to find composite vulnerabilities and assess layered defenses. It generates assurance trees tailored to each service and produces high-quality, actionable findings that speed remediation. Microsoft reports the system compresses deep security reviews from weeks to hours and that over 90% of findings were validated by engineers.
read more →

Gemini Enterprise for Education Named a Commander

🚀 Gemini Enterprise for Education has been named a Commander in the Tambellini StarChart™: 2026 AI Agents for Administrative Efficiency—Agent Platforms, ranking first in innovation and usability. The platform unifies Gemini models, agent-building tools, enterprise search, governance controls, and Google Cloud infrastructure to help institutions automate administrative workflows, support students, and enable research. Customers such as UC Riverside and Purdue report measurable operational and educational benefits from the integrated, governed agentic solution.
read more →

AI-Accelerated Cloud Attack Exploits Management Gaps

🔎 A Sygnia report details how a lone threat actor leveraged AI to complete in 72 hours what would normally take weeks, using established cloud attack techniques rather than novel exploits. The attacker obtained an AWS access key via an internet-facing app and used agentic AI workflows to search for secrets, establish persistence, exfiltrate RDS data, and perform impact actions. The report highlights gaps in secrets management, identity governance, deployment workflows and visibility, and provides containment recommendations for defenders.
read more →

Cybersecurity and the Growing Skill–Ability Divide

🛡️ The Five Eyes recently warned that AI models increasingly enable autonomous cyberattacks, amplifying risks long present in cyberspace. Bruce Schneier argues that AI widens the gap between skill and ability: tools let less-skilled actors cause damage once limited to experts. He warns guardrails from large vendors won’t stop open-source or locally run models and urges using AI defensively to detect, remediate, and respond faster to evolving threats.
read more →

NCSC unveils Cyber Shield: agentic AI for defence

🔒 The UK National Cyber Security Centre (NCSC) has launched the Cyber Shield initiative to build a national cyber-defence capability powered by agentic AI. The project will use coordinated red and blue agents to discover and mitigate vulnerabilities at scale, enable national automated scanning, and support real-time intelligence sharing. The NCSC says success requires partnerships with government, critical infrastructure and frontier AI providers.
read more →

Publishing AI Agents to Gemini Enterprise and Marketplace

🧭 This guide explains how to build, register, and commercialize AI agents as Agents-as-a-Service (AaaS) for deployment in the Gemini Enterprise app and Google Cloud Marketplace. It details required artifacts like the A2A Agent Card, authentication options including OAuth and Dynamic Client Registration (DCR), and the integration points for procurement, billing, and entitlement management. The article also outlines the seller journey, testing, and the end-to-end procurement and registration lifecycle across Billing Administrator, Discovery Engine Administrator, and end-user roles.
read more →