惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Microsoft Azure Blog
Microsoft Azure Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Webroot Blog
Webroot Blog
腾讯CDC
The Last Watchdog
The Last Watchdog
博客园 - 司徒正美
H
Hacker News: Front Page
I
InfoQ
A
Arctic Wolf
H
Hackread – Cybersecurity News, Data Breaches, AI and More
H
Heimdal Security Blog
L
LINUX DO - 最新话题
T
Threat Research - Cisco Blogs
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
Security Latest
Security Latest
D
DataBreaches.Net
C
Check Point Blog
J
Java Code Geeks
www.infosecurity-magazine.com
www.infosecurity-magazine.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Attack and Defense Labs
Attack and Defense Labs
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
Lohrmann on Cybersecurity
雷峰网
雷峰网
Vercel News
Vercel News
WordPress大学
WordPress大学
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Spread Privacy
Spread Privacy
Forbes - Security
Forbes - Security
阮一峰的网络日志
阮一峰的网络日志
Hacker News: Ask HN
Hacker News: Ask HN
大猫的无限游戏
大猫的无限游戏
I
Intezer
N
News and Events Feed by Topic
小众软件
小众软件
B
Blog RSS Feed
Help Net Security
Help Net Security
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 三生石上(FineUI控件)
S
Security @ Cisco Blogs
美团技术团队
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main

Forbes - Business

Pickleball Slam 4 Preview — History Of The Event And Behind The Scenes Prep With The Players How To Get Masters 2027 Tickets Lottery Dates And Odds ‘Malcolm In The Middle: Life’s Still Unfair’ Is Likely A Wrap For Show Tony Gonzales, Eric Swalwell Will Resign Following Sexual Misconduct Allegations Suspect In Sam Altman Molotov Attack Charged With Attempted Murder Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Dan Orlovsky Compares Ty Simpson To Brock Purdy, Names Surprising NFC Contender As Fit For 2026 NFL Draft Prospect IndyCar’s Chip Ganassi Racing, OpenAI Hope For ‘Competitive Advantage’ Shingles Altered Achilles Rehab For Pacers Star Tyrese Haliburton, But He’s Back On The Court NYT Pips Today: Hints, Answers And Walkthrough For Tuesday, April 14 LVMH Founder Bernard Arnault’s Fortune Falls $50 Billion This Year Inter Miami CF Kicks Off New Era For South Florida Soccer In Nu Stadium IndyCar’s AJ Foyt Racing Hires Toby Sowery As Reserve Driver IndyCar’s Chip Ganassi Racing Goes Green With Green Sports Alliance Rory McIlroy Claims Second Straight Masters Title At Augusta Rockets Claim Fifth Seed In West Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 Design Details In ‘The Drama’ Delve Deep Into Character AEW Dynasty 2026 Results, Winners And Live Updates On April 12 Former Dodgers Infielder, 3-Time MLB All-Star And Champion, Dies After Cancer Battle Townsend And Wild Secure Double Golds At Pro Pickleball Association Australia Moreton Bay Los Angeles Dodgers Prospect James Tibbs III Is Tearing Up Triple-A Hungary’s Authoritarian Orban—Boosted By Trump—Loses. European Leaders Celebrate. Review: Blackbraid Delivers Exteme Metal Masterclass To Dublin, Ireland Colorado Is Emerging As An Energy Innovation Hub U.S. Military Ships In Strait of Hormuz Violate Ceasefire, Iran Warns (Live Updates) Rosé’s All-Time Sales Chart Record Has Been Beaten IC3 Report Reveals Surge In Cryptocurrency Investment Scams The Top Contenders For The 2026 NCAA Gymnastics All-Around Title What Time Does ‘Euphoria’ Season 3 Come Out? How To Watch Tonight John Nolan, ‘Batman’ Films And ‘Person Of Interest’ Actor, Dies At 87 BTS Dominates The Biggest Songs Chart In America — Again Jannik Sinner Ties Novak Djokovic’s Masters 1000 Mark—Will Return To World No. 1 Will Iran War Result In Nuclear Weapon Transfers To The Middle East? Iran Reportedly Used Chinese Satellite To Target U.S. Bases—Here’s How China And Russia Could Help Iran Why Diesel Prices Spike Faster Than Gasoline In A Crisis UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami Taemin Dazzles At Coachella Debut And Premieres 6 New Songs: Full Setlist UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 WNBA Draft 2026 Date, Time, Order And Top Prospects Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction Avengers’ Biggest Battle? Taking On ‘Dune: Part Three’ At Christmas U.S.-Iran Peace Talks Stretch Into Sunday—As Iran Denies U.S. Navy Destroyers Passed Through Hormuz Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Why Dewey Actor Was Recast For ‘Malcolm In The Middle’ Revival Series Eric Swalwell Is Being Investigated In New York After Sexual Assault Claim Against Him Artemis Reached The Moon. The Grid Can Reach The 21st Century Pope Leo XIV Says 'Enough Of War!' As He Urges ‘Mediation’ To End Iran Conflict NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) U.S.-Iran Peace Talks Stretch Into Sunday—As Iran Denies U.S. Navy Destroyers Passed Through Hormuz Beyond Private Credit—The Overlooked Risks Of Banks’ Ties To Nonbanks ‘Euphoria’ Musician Labrinth Suggests He Was Treated Poorly Before Leaving Hit Show Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams UFC Tonight: What Time Does The UFC 327 Fight Card Start? Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records Harry Styles Flies With His Oldest Hit Thanks To A Box Office Smash New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU Chris Stapleton’s High-Profile Collaboration Becomes A Certified Hit Miley Cyrus Charts The Biggest New Sales Smash In America Pet Shop Boys’ Visual History Told In New Book China Seizes An Island While The World Is Watching Iran Ozzy Osbourne’s Name Helps A Rock Band Chart A New Top 10 Hit Forbes House of the Week: 3 Things We Crave Make U.S. Air Cargo More Valuable Than Ocean Ocean Tight Ends To Trade Away In Dynasty Fantasy Football Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns What’s At Stake In Hungary’s Election For Ukraine And Russia Coachella 2026: All 95 Surprise Guests Who Appeared This Year Coachella Accidentally Plays New KATSEYE EP Announcement Before Debut Performance KATSEYE Performs ‘Golden’ At Coachella with HUNTR/X voices KATSEYE Feature ‘KPop Demon Hunters’ Singers For 'Golden' At Coachella WWE SmackDown Results, Winners And Grades On April 10, 2026 WWE SmackDown Results As Pat McAfee Announces 25% Off WrestleMania 42 Tickets Bini Makes History For Filipino Music At Coachella 2026: Full Setlist 5 Under-The-Radar Winners And Losers In The Iran War So Far Menswear In The Post-Covid Age Is High Tech And High Touch Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 ‘Hacks’ Season 5 Release Schedule Reveals Final Episodes For Series Packers Trade Inconsistent Dontayvion Wicks To The Eagles Dan Levy’s Netflix Crime Comedy ‘Big Mistakes’ Takes Huge, Hilarious Risks Inside 30 Years Of Progress At The Wendy Hilliard Gymnastics Foundation With A $1.2 Billion Sale To Unilever, Grüns’ Founder Mints A Fortune What Does ‘You The Birthday’ Mean? TikTok’s Viral Phrase, Explained Kenny Omega Talks Comeback And Facing MJF At AEW Dynasty FIFA World Cup 2026: Why Ticket Scandals Still Cloud the Tournament Two Months Out Oldest US Navy Supercarrier Sailing In ‘Southern Seas 2026’ Exercises Huang Urges People To ‘Move To California’ As Billionaire Tax Looms BTS ARIRANG World Tour: What To Expect For New Fans And Old ‘You, Me & Tuscany’ Rotten Tomatoes Reviews Like Where Rom-Com Lands IRS Issues New ‘No Tax On Tips’ Rules—Here’s Who Qualifies Trump Wants To Build An Arch In D.C.—Here’s What It Would Look Like Molotov Cocktail Thrown At Sam Altman’s Home, OpenAI Says—Suspect Arrested
The Real AI Security Risk Isn't Data Leakage. It's What Your Agents Can Do
Güney Yıldız · 2026-05-11 · via Forbes - Business
Datalake Big Data Warehouse Data Lake Platform Analytics Technology

Agentic AI has moved the threat boundary inside the enterprise. Mindgard's Aaron Portnoy explains why authority, not access, is now the primary vulnerability.

getty

For most of the history of corporate cybersecurity, the central problem was access. Could the attacker get in? The defensive model followed: harden the perimeter, segment the network, control the gates, train the staff to recognize phishing. That logic still applies. It is no longer sufficient.

The more consequential new question is authority. What can the AI agent actually do once it is already inside?

Granting Code Agency

Aaron Portnoy, Chief Product Officer at AI security firm Mindgard, has been making this argument before it reached board agendas. In an earlier interview, he described the structural problem with a directness that most vendor materials avoid: "You are granting code agency."

That phrase is worth sitting with. An AI agent with enterprise permissions is not a chatbot. It can retrieve documents, query databases, write and execute code, open tickets, draft and send emails, move files, and trigger downstream workflows. It reads business context in natural language and acts on it. That capability is what makes it useful. It is also what makes it exploitable.

"I can coerce an internal asset to produce malicious content from the inside," Portnoy explained. "I'm not going to try to send that over the network. I'm just going to instruct in natural language to this agent, and it will build it and run it for me."

MORE FOR YOU

The attacker, in this model, does not need to defeat the firewall. He needs to construct a sentence the agent finds plausible.

The Compliance Trap

The boardroom conversation about AI security has so far centered on the wrong problem. Most governance frameworks are built around data leakage: an employee pasting proprietary content into a public model, a vendor training on private data, a model surfacing sensitive information in a response.

Those risks are real. They are also the ones that translate most easily into policy checklists and compliance slides. They are not the structural threat.

The harder problem is model coercion, and it sits outside the scope of most existing frameworks.

Recent analysis of enterprise AI governance drawing on McKinsey data captures the gap. Around 88% of organizations now use AI in at least one business function. But approximately two-thirds of board directors report limited or no AI experience. Fewer than a quarter of companies have board-approved AI policies. Only about 15% of boards receive AI-related metrics.

That describes an organization that has broadly adopted a technology its governance layer does not yet see clearly.

The Asymmetry Problem

Portnoy's second observation concerns speed. In the contest between attack and defense, the feedback loops are not equal.

"There's a bit of an asymmetry in the difficulty of using AI effectively for attackers and defenders," he noted, "mainly because attackers have a tight feedback loop. Right now it sure seems like attackers are adopting AI a lot faster than defenders."

This matters because of how prompt injection attacks are developed. An attacker can test thousands of variations of a malicious instruction — changing phrasing, disguising intent as routine business context, fragmenting a harmful task into individually benign steps. Each failure informs the next attempt. The iteration cost is low.

Defenders face a structurally harder task. They must protect systems that interact with messy, context-dependent natural language across every business function. A guardrail that blocks one attack may interrupt a legitimate workflow. A defense that holds today may fail tomorrow as context shifts.

Mandiant's M-Trends 2026 report records that state-sponsored and criminal actors are already using large language models for hyper-personalized social engineering and for malware that queries models mid-execution to evade detection. The baseline pattern of enterprise breaches remains human and systemic failure. The AI layer adds a new attack surface on top of the existing one.

When Language Meets Steel

The risk sharpens considerably when agentic AI is deployed in operational technology environments.

Energy operators, industrial manufacturers, and utilities are under genuine pressure to use AI. The complexity of modern energy systems — more intermittent renewable generation, growing data center load, volatile commodity inputs — creates real demand for AI-assisted dispatch, maintenance prioritization, anomaly detection, and asset monitoring.

An agent embedded in those workflows can add significant value. It can also become part of the control fabric in ways that are harder to govern than traditional enterprise software.

This is where Portnoy's third observation becomes most important: "You don't have access to the system or control how it's thinking. You only have access to the behavior, which is stochastic in nature. You may see it behave one way one day, and the next minute it's going to behave entirely differently."

Traditional operational technology runs on deterministic logic. A valve is open or closed. A breaker trips or it does not. Introducing a probabilistic decision layer into that environment is not inherently dangerous — industrial systems already use sophisticated software and optimization algorithms. The governance question is authority. What can the model change? What requires human approval? What happens if the agent's context is manipulated through a maintenance ticket, a supplier document, or a routine log it was asked to process?

Those are safety engineering questions that also have a cybersecurity answer. At the moment, they are rarely in the same room.

Gartner has forecast that by 2028, a quarter of enterprise breaches will be attributable to AI agent abuse. The direction is consistent with how deployment trajectories are moving.

Three Controls That Actually Matter

The standard enterprise response to AI security risk is to convert it into a governance exercise. Write acceptable-use policies. Approve the vendor. Review the data terms. Commission a training module.

That produces compliance. It does not produce operational security.

Three controls define the real posture for enterprise AI. Privilege determines what the model can actually do: which systems it can read, which it can write, which it can call. Context determines what the model is allowed to read and believe: what data it retrieves, which sources it trusts, what it treats as authoritative instruction. Blast radius determines how far a manipulated output can travel before a person or system intercepts it.

Most companies have thought carefully about the first. Fewer have fully addressed the second. Almost none can confidently answer questions about the third.

The missing operational step is adversarial testing: systematically trying to manipulate enterprise AI systems with the same creative pressure an attacker would apply, before an attacker does. Not annual penetration testing. Continuous, AI-assisted red-teaming of model behavior under adversarial prompting, in the actual environment where it runs, with the actual permissions it holds.

The Control Question

The near-term technical reality is more constrained than the threat picture implies. Enterprise agents today are still relatively narrow. Running them at meaningful scale is expensive. Many serious actions still require human approval.

But the constraints are easing. Costs are falling. Context windows are growing. Tool access is widening. The first generation of enterprise agents summarizes. The second drafts and recommends. The third will act with less supervision than the second.

Security frameworks need to track that progression rather than catch up to it after an incident.

The board question should be specific. Not: "Is our AI compliant?" But: "What can our AI agents do on a bad day — and does anyone in this room know the answer?"

The perimeter is not dead because firewalls failed. It is losing authority because companies are placing AI systems on the trusted side of the wall without fully accounting for what trust, in that context, actually means.

The new perimeter is a privilege model. For most organizations, it has not been designed yet.