Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface

July 23, 2026

Microsoft Copilot Deployments Delayed Over Security Concerns

July 23, 2026

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

July 23, 2026
Facebook X (Twitter) Instagram
Thursday, July 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Cyber Security

AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface

Team-CWDBy Team-CWDJuly 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The rapid adoption of enterprise AI tools is the fastest-growing source of new exposure for businesses, and it puts them at risk to additional cyber threats, a new report has warned.

Published on July 22, the Sophos AI Security 2026 Report, warned that AI identities have become a new attack surface as AI agents and assistants are adopted in the workplace.

Employees have deployed coding agents, agentic AI assistants, LLMs and other tools to help them with their work. It has become common for the agents to receive privileged access to core systems to aid with their efficiency.

Knowing this, cyber-attacks are targeting the trust, credentials and access permissions surrounding these systems, which has resulted in AI identities and AI agents becoming a high-value attack surface for malicious threat actors.

If access to these AI identities can be breached, it creates a new pathway into enterprise networks. That makes OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure targets for cybercriminals. But governance and security policies around AI identities have not kept pace with this new threat.

“Identity fabric connecting AI services to enterprise systems creates exposure that existing governance was not designed to handle,” warned Sophos.

This has happened at a time when the use of AI agents in the enterprise has grown exponentially. As the Sophos report cites, recent research by BeyondTrust detailed a 466.7% increase in active AI agents in enterprise environments in the last year.

The AI Governance Gap

Rapid AI adoption without proper governance means that organizations run the risk of exposure, especially if access to AI tools and enterprise platforms are secured with weak passwords.

Cybercriminals target workplace identities for several reasons, be it data theft, helping to deploy ransomware, as Sophos warned about in a previous report,  or other nefarious activities.

The privileges which some AI agents are awarded means that breaching AI identities could provide attackers with additional access to conduct attacks.

There is also the possibility that this kind of access could be used to gently manipulate or poison enterprise AI tools, subtly directing them to perform actions for the benefit of the attacker – and to the detriment to the victim organization and its users.

AI is also being used by threat actors to help with malicious campaigns including phishing attacks, social engineering and malware development.

“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations. That means the threat is in the here and now,” said John Peterson, CTO at Sophos.

 “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities,” he added.

To address the threat of cybersecurity incidents as result of compromised AI identities, the report recommended that AI agents should be treated like human users, with access restricted to just the applications and services they absolutely need to use.

The agent should also require manual verification to gain access to a new area, application or service.

Sophos also recommended that alerts should be set up to establish suspicious behavior or unexpected data exfiltration by AI agent identities.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Copilot Deployments Delayed Over Security Concerns
Team-CWD
  • Website

Related Posts

Cyber Security

Employees Are Misusing AI tools at Work

July 23, 2026
Cyber Security

Ubuntu snap-confine Vulnerability Enables Local Root Access

July 22, 2026
Cyber Security

Ferrari Cybersecurity Head on Defending Formula 1’s Most Iconic Team

July 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Common Apple Pay scams, and how to stay safe

January 22, 2026

In memoriam: David Harley

November 12, 2025

Why that next data breach alert could be a trap

April 18, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.