AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
What CISOs need to get right as identity enters the agentic era
Apr 28, 2026InfoNewsSecurityIndustryS&P Global CISO Dustin Wilcox and Docusign CISO Michael Adams argue that AI agents are a new class of non-human identity that existing identity models and inventory processes handle poorly. They advise CISOs to adopt an identity-first security model, starting with clean directories, enforced least privilege, reliable offboarding, and a complete inventory of non-human identities and their owners and authorizations.
Fix: Build a strong identity foundation first (clean directories, enforced least privilege, reliable offboarding). Design access policies from least privilege rather than legacy structures. Build a full non-human identity inventory that records each identity's owner and authorized actions, before more agents operate. Treat MFA as a starting point and move to phishing-resistant alternatives to SMS or push-based MFA. Apply least privilege, micro-segmentation and continuous monitoring, and assume credentials may be compromised.
CSO OnlineParsing Agentic Offensive Security's Existential Threat
Apr 27, 2026InfoNewsSecurityIndustrySome people fear that frontier LLMs such as Claude Mythos and Anthropic's GPT-5.5 will lead to cybersecurity annihilation. Ari Herbert-Voss argues this could instead be an opportunity.
Dark ReadingThe ‘manager of agents’: How AI evolves the SOC analyst role
Apr 27, 2026InfoNewsIndustryThe article argues that agentic AI elevates the Tier 1 SOC analyst from performing repetitive investigation steps to overseeing a system of AI agents, shifting the role from operator to orchestrator. It states that a typical phishing alert investigation takes 20–30 minutes of pivoting across email logs, endpoint data and threat intelligence tools. The author contends that AI will expose the unmet workload in security operations rather than eliminate analyst jobs.
CSO OnlineSBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation
Apr 27, 2026InfoResearchPeer-reviewedSecurityResearchACM Digital Library (TOPS, DTRAP, CSUR)Choco automates food distribution with AI agents
Apr 26, 2026InfoNewsIndustryChoco, an AI-powered food and beverage distribution platform serving over 21,000 distributors and 100,000 buyers, built OrderAgent and VoiceAgent on OpenAI APIs to turn emails, texts, voicemails, images and phone orders into structured ERP orders. The company reports processing over 8.8 million orders annually and up to a 50% reduction in manual order entry.
OpenAI BlogBenchmarking the effectiveness of multi-agent LLMs in collaborative privacy threat modeling with <span class="small-caps">LINDDUN GO</span>
Apr 26, 2026InfoResearchPeer-reviewedResearchPrivacyElsevier Security JournalsWhy Cybersecurity Must Rethink Defense in the Age of Autonomous Agents
Apr 24, 2026InfoNewsSecurityIndustryAt RSA Conference in March 2026, the industry focused on agentic AI, meaning AI systems that act as autonomous actors. The Cloud Security Alliance predicts a rise in simultaneous AI-powered attacks and urges defenders to fight AI with AI. The article argues that organizations should treat AI agents as identities and place them under identity threat detection rather than adding more point tools.
Fix: The article recommends treating AI as an identity and applying identity threat detection and risk mitigation, including behavioral visibility, risk-based controls, unified policy enforcement across human and machine identities, and lifecycle management to prevent orphaned or unmanaged agents. It also states that identity-driven security enforces least privilege and continuously validates access.
SecurityWeekBridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
Apr 24, 2026InfoNewsSecurityIndustryOrchid argues that enterprises face a delegation gap rather than a simple agent gap, since AI agents act on authority delegated by existing human and machine identities. The article says agents must be governed through the posture and intent of their delegators, with continuous observability of traditional identities as the foundation. The source text is cut off before it describes the full authority engine.
The Hacker NewsCopperhelm Raises $7 Million for Agentic Cloud Security Platform
Apr 24, 2026InfoNewsIndustrySecurityIsrael-based Copperhelm emerged from stealth after raising $7 million in seed funding, led by TLV Partners, for its agentic cloud security platform. The platform deploys AI agents that monitor cloud environments, investigate threats, and execute remediation in real time, using a component called the Context Lake.
SecurityWeekBad Memories Still Haunt AI Agents
Apr 23, 2026LowNewsSecuritySafetyCisco found and fixed a significant vulnerability in how Anthropic handles memories. Experts warn that mishandled memory files will continue to threaten AI systems.
Dark ReadingGoogle drafts AI agents secure systems against AI hackers
Apr 23, 2026InfoNewsSecurityIndustryAt Google Cloud Next '26, Google responded to Anthropic Mythos with a push toward agentic, AI-driven defense rather than another LLM. It announced three agents in Google Security Operations (threat hunting, detection engineering, and third-party context), expanded Wiz integration for AI development environments, and the Gemini Enterprise Agent Platform.
Fix: Google's stated measures include Model Armor, which the source says is integrated to mitigate risks like prompt injection and data leakage, plus Agent Identity and Agent Gateway for governance and policy enforcement. The source does not describe a fix for a specific vulnerability.
CSO OnlineIntroducing GPT-5.5
Apr 23, 2026InfoNewsIndustryOpenAI released GPT-5.5, which it describes as its smartest model yet, with gains in agentic coding, computer use, knowledge work and early scientific research. It rolls out to Plus, Pro, Business and Enterprise users in ChatGPT and Codex, and GPT-5.5 Pro to Pro, Business and Enterprise users in ChatGPT, with API access to follow later.
OpenAI BlogCVE-2026-41679: Paperclip unauthenticated remote code execution through its API
Apr 22, 2026CriticalVulnerabilitySecurityCVE-2026-41679Paperclip, a Node.js server and React UI for orchestrating AI agents, is affected by CVE-2026-41679 in versions prior to 2026.416.0. An unauthenticated attacker can achieve full remote code execution on any network-accessible instance running in `authenticated` mode with default configuration, using a six-call API chain requiring no credentials or user interaction.
Fix: Version 2026.416.0 patches the issue.
NVD/CVE DatabaseCVE-2026-41208: Paperclip server privilege escalation through adapterConfig endpoint
Apr 22, 2026HighVulnerabilitySecurityCVE-2026-41208Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation flaw. Agents can update their own adapterConfig through the /agents/:id endpoint, and the server later executes adapterConfig.workspaceStrategy.provisionCommand during workspace provisioning. An attacker holding an Agent API key can inject shell commands that run on the Paperclip server host, which the source describes as remote code execution.
Fix: @paperclipai/server version 2026.416.0 fixes the issue.
NVD/CVE DatabaseNow Meta will track what employees do on their computers to train its AI agents
Apr 22, 2026InfoNewsPrivacyIndustryMeta is installing a tool called Model Capability Initiative (MCI) on US-based employees' computers. It records mouse movements, clicks, keystrokes, and occasional screenshots in work-related apps and websites, and the data will train the company's AI models to interact with computers like humans, including automating work tasks. According to Reuters, the data won't be used for performance assessments.
The Verge (AI)From Access Control to Outcome Control: Securing AI Agents with Check Point and Google Cloud
Apr 22, 2026InfoNewsSecurityIndustryCheck Point and Google Cloud describe securing AI agents by controlling what agents are allowed to do, not only who can access systems. Google Cloud's Gemini Enterprise Agent Platform is presented as a centralized control point for agentic systems, covering identity, access, policy enforcement, and observability. The source text is truncated before any further detail.
Check Point ResearchSpeeding up agentic workflows with WebSockets in the Responses API
Apr 22, 2026InfoNewsIndustryOpenAI describes how it made agent loops on the Responses API 40% faster end-to-end, so Codex could run GPT-5.3-Codex-Spark at near 1,000 tokens per second instead of the roughly 65 TPS of prior flagship models. The gains came from caching rendered tokens and model configuration, removing intermediate network hops, speeding up safety classifiers, and adding a persistent WebSocket connection in place of repeated synchronous HTTP calls.
OpenAI BlogBuilding agent-first governance and security
Apr 21, 2026InfoNewsIndustrySecurityDeloitte's AI Institute 2026 State of AI report finds nearly 74% of companies plan to deploy agentic AI within two years, yet only 21% report a mature governance model for autonomous agents. The article argues that insecure agents can be manipulated into reaching sensitive systems and data, and that a centralized control plane governing agents, their permissions, policies, models and tools is needed to scale them safely.
MIT Technology ReviewClosing the Security Gap in the Age of Agentic Coding
Apr 21, 2026InfoNewsSecurityIndustryWiz has added Wiz Code plugins and skills, powered by the Wiz MCP server and WizCLI, that bring its security context into AI-native IDEs and coding agents. The tooling scans AI-generated code in real time and lets coding agents apply Green Agent remediation guidance, which can create pull requests. The announcement responds to frontier models such as Anthropic's Claude Mythos Preview, which the source says can autonomously discover and exploit zero-day vulnerabilities.
Fix: The source describes the Wiz Code plugins, skills, Green Agent remediation plans and automated scans at file save, pre-commit and pre-push as the approach; it does not state a patch, fixed version or configuration fix for a specific vulnerability.
Wiz Research BlogCVE-2026-39861: Claude Code sandbox escape through symlinks outside the workspace
Apr 20, 2026HighVulnerabilitySecurityCVE-2026-39861Claude Code versions before 2.1.64 let sandboxed processes create symlinks pointing outside the workspace. When Claude Code later wrote through such a symlink, its unsandboxed process followed it and wrote to the external target without asking the user for confirmation, enabling a sandbox escape that could potentially lead to code execution outside the sandbox. Exploitation required injecting untrusted content into the Claude Code context window to trigger sandboxed code execution.
Fix: Fixed in version 2.1.64. Users on standard auto-update received the fix automatically; users performing manual updates are advised to update to version 2.1.64 or later.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.