Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

How Proton Fights Against Cybercriminals Using Its Services

June 5, 2026

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

June 5, 2026

Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts

June 5, 2026
Facebook X (Twitter) Instagram
Friday, June 5
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AI Coding Tools Need Built-In Security for Agentic Development Era
News

AI Coding Tools Need Built-In Security for Agentic Development Era

Team-CWDBy Team-CWDJune 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security must be embedded directly into AI coding tools to mitigate emerging risks associated with agentic development, Ox Security has claimed.

Speaking at Infosecurity Europe on June 4, the vendor’s field CTO, Boaz Barzel, explained that traditional application security was built for human-paced delivery.

That meant pen testing at the end of the monthly delivery cycle. However, AI agents now enable hundreds of code changes per day in a continuous cycle, meaning security can no longer be a bolt-on, Barzel argued.

“The idea is that security isn’t a stage in the pipeline; it’s a property of the act of creation itself,” he told attendees. “We’re trying to shift left, but there’s no longer ‘left’ left to shift to. We have to shift into the agent.”

Read more on agentic security risk: Threat Actor Uses AI to Build EDR Evasion Tools.

AI agents introduce four distinct attack surfaces that traditional tools are not equipped to handle, Barzel explained:

  • Input: Any instructions (eg prompts, guidelines, protocols) entering the agent – be they from developers, upstream agents or threat actors
  • Tools: MCP servers, models, skills and external SaaS connections (shadow and authorized) which could be weaponized to exfiltrate data, inject instructions or pivot laterally
  • Execution: Both human-triggered and autonomous agents running without visibility, enforcement or accountability
  • Output: Vulnerable or destructive code leaving the agent (eg path traversal, injection, backdoors, exfiltration logic) at machine speed without human review

These challenges are compounded by the collapse of the exploitation window thanks to powerful frontier models like Mythos, which could reduce time-to-exploit to minutes. And by the sheer volume of code that AI tools can generate.

Understanding the Auto-Pentest Loop

To make appsec fit for the agentic AI era, it must be embedded in the building loop, contextual and operating continuously, said Barzel.

This means security agents working alongside coding agents, with every commit pentested and every fix reviewed and validated autonomously. The system reasons about what has changed, what is exposed and what risk it introduced, so that it is predictive, not reactive, he explained.

“In this case, security stops being a department. It becomes a behavior of the system,” Barzel added.

The aim is for:

  • Mean time to resolve (MTTR) vulnerabilities to fall from weeks to hours
  • 100% coverage of autonomous security checks for merged changes
  • Reduction in the time a known risky path is reachable in production before being gated or fixed
  • Most issues to be autonomously fixed and validated, with humans only needed to assess more complex or novel issues

New agentic coding risks are being uncovered on a regular basis. For example, in May 2026, a critical vulnerability was discovered in the Cline Kanban server which could allow threat actors to silently hijack AI coding tools.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleJINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
Next Article OWASP Introduces Agentic AI Security Maturity Framework
Team-CWD
  • Website

Related Posts

News

How Proton Fights Against Cybercriminals Using Its Services

June 5, 2026
News

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

June 5, 2026
News

Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it is and how to protect yourself

January 8, 2026

What to consider before asking an AI chatbot for health advice

May 27, 2026

Top IRS scams to look out for in 2026

February 10, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.