AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
573 items
Deterministic + Agentic AI: The Architecture Exposure Validation Requires
Apr 15, 2026InfoNewsIndustrySecurityPentera's AI Security and Exposure Report 2026 says every surveyed CISO reports AI already in use across their organizations. The article argues that security validation needs AI for adaptive testing, but that fully agentic systems, where AI reasoning governs execution end to end, undermine the repeatability that structured security programs require. It proposes a hybrid model in which deterministic logic defines attack chain execution and AI adapts payloads within that structure.
The Hacker NewsCurity looks to reinvent IAM with runtime authorization for AI agents
Apr 14, 2026InfoNewsSecurityIndustrySwedish vendor Curity announced Access Intelligence, an extension to its Identity Server API IAM platform, to secure autonomous AI agents. Its approach treats agents as a special type of application, issuing OAuth tokens that carry the agent's purpose and intent, with access granted per action at runtime rather than through static permissions.
CSO OnlineSecure AI agent access patterns to AWS resources using Model Context Protocol
Apr 14, 2026InfoNewsSecurityIndustryThis AWS blog post explains how to secure AI agents and coding assistants that access AWS resources through the Model Context Protocol (MCP). It argues that agents can do anything their granted entitlements allow, so IAM permissions must be designed as deterministic controls, and it presents three IAM security principles with policy examples.
AWS Security BlogEnterprises power agentic workflows in Cloudflare Agent Cloud with OpenAI
Apr 13, 2026InfoNewsIndustryCloudflare is making OpenAI frontier models, including GPT-5.4, available to millions of customers within Agent Cloud, a platform for deploying AI agents that handle tasks such as responding to customers, updating systems and generating reports. The Codex harness is now generally available in Cloudflare Sandboxes and will come to Workers AI in the near future.
OpenAI BlogThe agentic SOC—Rethinking SecOps for the next decade
Apr 9, 2026InfoNewsIndustrySecurityMicrosoft describes the agentic SOC, a security operations model that moves from reacting to incidents toward anticipating attacker movement and reshaping the environment to cut off their paths. The model pairs a threat protection platform with built-in autonomous defense and AI agents that assist analysts with investigation and prioritization. The article is the opening of a series and points to a new whitepaper, The agentic SOC: Your teammate for tomorrow, today.
Microsoft Security BlogMicrosoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
Apr 8, 2026InfoNewsSecurityIndustryMicrosoft has released the Agent Governance Toolkit, an open-source project that monitors and controls AI agents during execution. It adds a runtime security layer that enforces policies against issues such as prompt injection and maps to OWASP's top 10 risks for agentic systems. The toolkit is in public preview under an MIT license, with components in Python, TypeScript, Rust, Go and .NET.
CSO OnlineThe New Rules of Engagement: Matching Agentic Attack Speed
Apr 7, 2026InfoNewsSecurityIndustryThe source argues that the cybersecurity response to AI-enabled nation-state threats cannot be incremental and must instead be architectural. It is a short opinion piece with no further details on specific attacks, products or figures.
SecurityWeekFlowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
Apr 7, 2026MediumNewsSecurityIndustryThreat actors are exploiting CVE-2025-59528 (CVSS 10.0), a code injection flaw in Flowise's CustomMCP node that executes user-supplied JavaScript in the mcpServerConfig string without validation. Successful exploitation allows access to child_process and fs, leading to full system compromise, according to VulnCheck. VulnCheck reports 12,000+ exposed Flowise instances, and the flaw was publicly known for more than six months.
Fix: The issue was addressed in version 3.0.6 of the npm package.
The Hacker NewsGoogle DeepMind Researchers Map Web Attacks Against AI Agents
Apr 6, 2026InfoNewsSecurityResearchGoogle DeepMind researchers have mapped a vulnerability category called 'AI Agent Traps'. The source says it lets attackers manipulate, deceive, and exploit AI agents that visit malicious web content.
SecurityWeekFour security principles for agentic AI systems
Apr 2, 2026InfoNewsSecurityPolicyAWS submitted a response to NIST's Center for AI Standards and Innovation (CAISI) Request for Information on securing agentic AI systems, which act autonomously by connecting to tools and APIs and using LLMs to plan and execute actions at machine speed. The response identifies four foundational security principles and the architectural building blocks that implement them. The source excerpt ends before the remaining principles are described.
AWS Security BlogHighlights from my conversation about agentic engineering on Lenny's Podcast
Apr 2, 2026InfoNewsIndustrySafetySimon Willison was a guest on Lenny Rachitsky's podcast, in an episode released 2 April 2026, discussing agentic engineering. The source highlights his view that GPT 5.1 and Claude Opus 4.5 marked an inflection point in November, after which coding agents mostly do what they are told. He argues that software engineers are a bellwether for other information workers.
Simon Willison's WeblogVariance Raises $21.5M for Compliance Investigation Platform Powered by AI Agents
Apr 2, 2026InfoNewsIndustryVariance has raised $21.5 million for its compliance investigation platform, which is powered by AI agents. The company has raised $26 million in total funding, and the latest investment is intended to fuel platform growth.
SecurityWeekWebinar Today: Agentic AI vs. Identity’s Last Mile Problem
Apr 1, 2026InfoNewsIndustrySecurityWeek promotes a webinar on what Agentic AI can and cannot solve today. The session also covers real-world breach scenarios tied to disconnected applications.
SecurityWeekGoogle Addresses Vertex Security Issues After Researchers Weaponize AI Agents
Apr 1, 2026MediumNewsSecurityIndustryPalo Alto Networks has disclosed the details of its analysis of Google Cloud Platform's Vertex AI. The source text provides no further technical detail about the issues or their consequences.
SecurityWeekHow to Categorize AI Agents and Prioritize Risk
Mar 31, 2026InfoNewsSecurityPolicyThe article argues that enterprise AI is shifting from chatbots that answer questions to AI agents that reason, plan, and act across enterprise systems autonomously. It states that the security risk of an agent depends on its access to systems and data and on how independently it can act without human approval.
BleepingComputerDouble Agents: Exposing Security Blind Spots in GCP Vertex AI
Mar 31, 2026MediumNewsSecurityResearchPalo Alto Networks' Unit 42 researchers showed that a deployed AI agent on Google Cloud Platform's Vertex AI Agent Engine, built with the Application Development Kit (ADK), could be weaponized. By exploiting excessive default permissions on the Per-Project, Per-Product Service Agent (P4SA), they extracted a service agent's credentials and gained privileged access to data in a consumer project, as well as restricted images and source code in a producer project. After the researchers shared their findings, Google revised its documentation to explain how Vertex AI uses resources, accounts and agents.
Fix: Google revised its official documentation to explicitly document how Vertex AI uses resources, accounts and agents. The source does not describe any other fix, configuration change or workaround.
Palo Alto Unit 42Addressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio
Mar 30, 2026InfoNewsSecurityIndustryMicrosoft's blog post discusses the OWASP Top 10 for Agentic Applications (2026), which outlines risks for autonomous systems that act across workflows using real identities, data access and tools. The post explores the list's key findings and highlights practical mitigations grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio. Microsoft AI Red Team members helped review the list before publication.
Fix: Practical mitigations are referenced as grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio, but the source text provided is truncated before the specific mitigations are described.
Microsoft Security BlogOkta’s CEO is betting big on AI agent identity
Mar 30, 2026InfoNewsIndustryPolicyOkta CEO Todd McKinnon discusses how the company is responding to pressure from AI, including the idea that customers could build their own tools instead of paying for SaaS. The interview also covers managing AI agent identity, which McKinnon describes as lying between a person and a system, and the need for a kill switch at the agent level.
The Verge (AI)Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
Mar 27, 2026InfoNewsIndustryPolicyAnecdotes co-founder and CEO Yair Kuznitsov argues that enterprise GRC teams hesitate to adopt agentic GRC mainly because of an identity and value question, not technology. He contends that agents can take over evidence gathering, remediation tracking and audit cycles, so practitioners must redefine their role around risk management and the judgment needed to design and oversee agent logic.
BleepingComputerPreparing for agentic AI: A financial services approach
Mar 26, 2026InfoNewsSecurityPolicyAWS describes security principles for deploying agentic AI in financial services, focusing on observability of agentic workflows and fine-grained control over agent tool access permissions. The post presents seven design principles and implementation guidance for meeting regulatory requirements, including SR 11-7 in the US, SS1/23 in the UK, and ECB guidelines in the EU.
AWS Security Blog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.