惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Comments on: Blog
S
Schneier on Security
Microsoft Azure Blog
Microsoft Azure Blog
T
Tor Project blog
V
Visual Studio Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
月光博客
月光博客
罗磊的独立博客
Cisco Talos Blog
Cisco Talos Blog
P
Privacy International News Feed
T
Tenable Blog
阮一峰的网络日志
阮一峰的网络日志
AWS News Blog
AWS News Blog
T
ThreatConnect
博客园 - 三生石上(FineUI控件)
Recorded Future
Recorded Future
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
博客园 - 叶小钗
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
A
Arctic Wolf
L
LINUX DO - 最新话题
美团技术团队
大猫的无限游戏
大猫的无限游戏
I
Intezer
博客园 - 司徒正美
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
小众软件
小众软件
T
Threatpost
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
The Register - Security
The Register - Security
Project Zero
Project Zero
J
Java Code Geeks
Cyberwarzone
Cyberwarzone
IT之家
IT之家
MyScale Blog
MyScale Blog
T
Threat Research - Cisco Blogs
T
The Blog of Author Tim Ferriss
腾讯CDC
S
SegmentFault 最新的问题
F
Fox-IT International blog
S
Security Archives - TechRepublic
Last Week in AI
Last Week in AI
G
GRAHAM CLULEY
M
MIT News - Artificial intelligence

Citrix Blogs

the Citrix AI Hotsheet – Citrix Blogs What is Citrix DaaS Flex, and why desktop modernization needs a different operating model – Citrix Blogs The secure access model needs a rethink: Introducing Citrix Platform Flex – Citrix Blogs AI is moving fast. Your infrastructure needs to keep up. – Citrix Blogs Why enterprise AI agents disappoint (and why the fix is not “better agents”) – Citrix Blogs Simplifying operations, reducing risk, and driving better outcomes with Citrix LAS – Citrix Blogs Announcing Citrix SDS support on Nutanix NKP: Solving the developer platform puzzle – Citrix Blogs A reflection – Citrix Blogs The SaaSpocalypse won’t touch the enterprise software moat – Citrix Blogs Celebrating the Partners powering Citrix forward – Citrix Blogs What’s left for humans? – Citrix Blogs Why this moment feels different – Citrix Blogs Introducing Citrix Platform for Public Sector – Citrix Blogs how our partnership with Google has matured secure access for the browser era – Citrix Blogs When session recording stops scaling – Citrix Blogs A conversation with Cletis Earle – Citrix Blogs Imprivata Ready Certification validates Citrix Unicon: A practical guide for healthcare IT – Citrix Blogs Skills are all you need – Citrix Blogs UHMC customers now have expanded Citrix Secure Private Access entitlement – Citrix Blogs How CIOs turn post‑merger disorder into a synergy engine – Citrix Blogs why your AI strategy is focused on the wrong layer – Citrix Blogs Securing high privileged admin access doesn’t have to be complicated – Citrix Blogs What will knowledge work be in 18 months? Look at what AI is doing to coding right now. – Citrix Blogs Untangling spaghetti – Citrix Blogs Workers’ “second brains” break every assumption about how we secure knowledge work – Citrix Blogs Taming integration chaos (the core of M&A failure) – Citrix Blogs OpenClaw and Moltbook preview the changes needed with corporate AI governance – Citrix Blogs Three years. Five Use Cases. A Leader: Citrix – Citrix Blogs The hard truths about hospital consolidation: An M&A guide for IT leaders Why Citrix is the most complete EUC platform – Citrix Blogs Sign in once, get more done: Why continuous identity is a strategic advantage Everyone’s worried about the wrong AI security risk Security by design, proven by action with Citrix NetScaler The invisible 80%—what corporate-led AI transformations can’t see Workers don’t want to build automations. They want to delegate. The CIO’s M&A integration dilemma: speed vs. security AI will be THE interface to knowledge work. Here’s how we’ll get there. Why I joined Citrix — and what it means for healthcare leaders How the most successful CIOs are building successful merger and acquisition approaches IT admits workers control AI. Workers admit they use it to leave at 5. One identity. Every app. Now inside Citrix sessions. – Citrix Blogs Built-in AI intelligence that keeps IT focused – Citrix Blogs Everyone wants to provide your AI. Nobody wants to help you manage it. Certificate lifetimes are shrinking—your business continuity doesn’t have to: Automating SSL/TLS at scale with NetScaler – Citrix Blogs Advancing Zero Trust at the browser – Citrix Blogs Citrix is headed to Microsoft Ignite 2025 as a Partner of the Year Finalist, top sponsor, and more! – Citrix Blogs Three trends reshaping how work happens – Citrix Blogs Our vision for secure access in a browser-first world – Citrix Blogs Will AI need to operate your legacy desktop apps or is direct file manipulation enough? – Citrix Blogs an executive blueprint for streamlined app delivery – Citrix Blogs AI just created 10,000 accidental citizen developers in your company. Welcome to the post-application era! – Citrix Blogs Why healthcare IT leaders are embracing Unicon + Imprivata – Citrix Blogs Windows 10 & IGEL OS 11 end-of-life: How Unicon OS turns deadlines into competitive advantage – Citrix Blogs The bitter lesson of workplace AI: Stop engineering, start enabling – Citrix Blogs If AI is normal technology, boring infrastructure is your best strategy – Citrix Blogs Innovation, efficiency, and the future of licensing – Citrix Blogs Worker-led AI isn’t shadow IT. It’s shadow strategy. – Citrix Blogs Everyone’s wrong about why enterprise AI is failing – Citrix Blogs Citrix Virtual Apps and Desktops 2507 Long Term Service Release is now available: Get current, stay ahead – Citrix Blogs If AI progress stopped today, we can still transform the enterprise with what we have – Citrix Blogs Leading the quantum-ready transition: How NetScaler helps prevent a silent data breach decades in the making What happens when AI agents score 100% in computing using benchmarks? Now available: Citrix DaaS for Amazon WorkSpaces Core Managed Instances Why AI agents will use the same desktops and apps as human workers – Citrix Blogs Modern applications need modern networking — Here’s what that means for your business – Citrix Blogs Powering your present, readying your future, and now available for all workloads – Citrix Blogs To understand AI’s future impact, check out this playbook from 150 years ago – Citrix Blogs The 7-stage roadmap for human-AI collaboration in the workplace – Citrix Blogs Secure your business with Citrix and Google Chrome Enterprise Premium – Citrix Blogs AI agents need a secure place to work. The Citrix workspace is ready. – Citrix Blogs What’s New and Next with Citrix: Q&A from our May 2025 webinar – Citrix Blogs What if your CEO never sends the AI-first memo? – Citrix Blogs Your CEO just sent a company-wide “AI-First” memo. Now what? – Citrix Blogs Citrix and Nutanix team up to simplify virtual desktop management – Citrix Blogs eLux + Imprivata coming soon for healthcare and beyond – Citrix Blogs Rising costs. Aging hardware. One smart solution. – Citrix Blogs The desktop has dissolved. Now where does work live in 2025? What’s new with Citrix: Citrix Virtual Apps and Desktops 2503 is now generally available What does “AI” mean at Citrix? Making sense of AI in the workplace: A starting point for leaders Control the endpoint, control the experience – Citrix Blogs Why I joined Citrix and what I’m excited about – Citrix Blogs Citrix’s approach to Secure by Design Citrix and NVIDIA partner to deliver AI Virtual Workstations – Citrix Blogs Welcoming Google Chrome Enterprise Premium into the Citrix platform – Citrix Blogs Apple M4 chip delivers another significant performance boost to Citrix VDA for macOS! – Citrix Blogs Updated STIG guidance for highly secure environments – Citrix Blogs It’s time to upgrade your hypervisor to XenServer 8! – Citrix Blogs Furthering our investment in the Citrix platform with the strategic acquisition of Unicon – Citrix Blogs Faster logins, more productivity – Citrix Blogs Experience the difference: New optimization for Microsoft Teams in Citrix environments Password spraying attacks on NetScaler/NetScaler Gateway – December 2024 – Citrix Blogs Citrix Secure Private Access delivers ZTNA in hybrid mode – Citrix Blogs Citrix strengthens zero trust security posture with strategic acquisitions of deviceTRUST and Strong Network – Citrix Blogs Ease your virtual machine device management with MCS & Intune – Citrix Blogs Free uberAgent training is now available on Pluralsight Improved security, admin interfaces, and user experiences across the Citrix solution portfolio – Citrix Blogs Citrix ranked highest for all 4 Use Cases in the Gartner® Critical Capabilities for Desktop as a Service Report – Citrix Blogs Join us at Microsoft Ignite – Citrix innovations for the modern workplace – Citrix Blogs Improve user experiences and reliability with new expanded uberAgent entitlements – Citrix Blogs
AI agents are the new insider threat. Secure them like human workers. – Citrix Blogs
2025-08-04 · via Citrix Blogs

Last week, security researchers demonstrated they could trick AI coding agents into running destructive commands by hiding malicious instructions in documentation. This wasn’t some complex zero-day exploit—it was essentially just classic social engineering. (Except the “person” being socially engineered was an AI agent, which means it had perfect memory and zero skepticism, so the malicious instructions were followed dutifully!)

If this sounds absurdly simple, that’s because it is, with several examples circulating recently. This perfectly illustrates why we need to think of AI agents as being no different than human workers, applying the same guardrails and security protections to both.

AI agents are autonomous workers, not tools

For decades, we’ve built sophisticated trust models for human workers which compensate for our flawed, emotional, and fallible behaviors. We’ve created entire security frameworks around the ways that humans can be compromised: access controls, DLP, session monitoring, authentication systems, behavioral analytics, etc.

Now that we’re starting to think about deploying AI agents that can read, write, execute code, access applications, and make decisions, we need to realize that these aren’t tools anymore, they’re autonomous workers operating inside our systems. So we need to treat them like any other worker who can be compromised.

Sure, the specific attack vectors are different—prompt injection instead of phishing or poisoned training data instead of social engineering—but the fundamental risk is the same. You have an autonomous entity with privileged access that can be manipulated to act against your interests.

If your AI doesn’t have an identity, your attacker will give it one

In my 7-stage roadmap for human-AI collaboration, one of the differences between Stage 4 (AI uses your computer) and Stage 5 (AI uses your computer without you watching) is that AI agents will need their own identities, rather than running via the logged-on human worker’s credentials, service accounts, or a shared API key anyone can use.

This will be a non-negotiable requirement, as having AI agents running without their own identities is no different than having workers in your building without badges. Sure, they might be doing legitimate work, but without an ID, you can’t track what they’re doing, limit where they can go, or even know they’re there.

Luckily the industry is waking up to this. Microsoft recently announced Entra Agent ID, dedicated, first-class identity objects specifically for AI agents. It’s their recognition that AI agents need to be treated like employees in your identity system, not just background processes hiding behind a human’s credentials.

Without a defined identity, an attacker can effectively assign one. They can make your AI agent do whatever they want, and you wouldn’t even know it’s not following your instructions. The agent becomes a perfect insider threat that never sleeps, never questions orders, and operates stupidly fast.

The AI agent attack surface is massive (and growing)

Consider all the ways human workers can be compromised:

  • Phishing emails that trick them into revealing credentials
  • Social engineering that manipulate them into breaking protocol
  • Malware on their devices that captures their actions
  • Insider threats where they intentionally cause harm

Now consider the AI agent equivalent:

  • Prompt injection attacks that override the AI’s instructions
  • Data poisoning that corrupts the AI’s decision-making
  • Adversarial inputs that cause the AI to malfunction
  • Supply chain attacks through compromised models, training data, or applications

The researchers who compromised the AI coding agents didn’t need sophisticated tools. They just needed to understand that AI agents, like humans, trust their inputs. If you give them bad data, they’ll act on it, except unlike humans, they’ll do it perfectly, consistently, and without hesitation.

Why traditional security doesn’t work here

The knee-jerk reaction is to try to “fix” the AI: make it smarter, add more filters, train it to detect malicious inputs, etc. This is like trying to create a human who can never be phished. It’s a fool’s errand. (Though many hours of HR training videos certainly try!)

The other common approach is to restrict what AI can do: limit its access, constrain its actions, and wrap it in so many controls that it becomes useless. This is like hiring an amazing worker and locking down their work environment so tight that they can’t actually get their job done.

Neither approach works because they’re trying to solve the wrong problem. The issue isn’t that AI can be compromised, it’s that we’re not treating AI compromise as inevitable and building our security accordingly.

The solution: Treat AI agents like you treat humans

As AI enters your workplace, it’s important to understand that identity, access, and intent are no longer just human concepts, and that moving forward they will be part of every worker—human or AI—in your digital workplace.

When a human worker logs into your systems:

  • Their identity is verified
  • Their access is controlled by role-based permissions
  • Their actions are logged and monitored
  • Anomalous behaviors trigger alerts
  • Sensitive actions require additional authorization
  • Their sessions can be recorded and audited

When an AI agent operates in your systems, it needs:

  • A verified identity (for the agent, not the human the agent is working on behalf of)
  • Role-based access controls (what can this specific AI do?)
  • Complete action logging (every decision, every output)
  • Behavioral analytics (is this AI acting normally?)
  • Authorization workflows (human approval for sensitive operations)
  • Session recording (what did the AI see and do?)

Again, this isn’t about making AI “safer” per se, it’s about acknowledging that AI agents, like humans, operate in unsafe ways in an unsafe world, and appropriate controls need to be built around that.

Secure the work, regardless of who (or what) does it

The good news is that if you treat your AI agents like humans, then you’re already most of the way down the path of securing them in your environment. This is how we think about AI agents at Citrix. We’ve spent 35 years building guardrails for secure workspaces operated by human workers. Now those same controls—identity management, access control, session monitoring, anomaly detection—need to extend to AI workers.

The principle remains the same: secure the work itself, not just the worker. Whether that worker is human or AI, in the office or remote, using a managed device or their own—the work needs to be secured at the point where it happens.

AI agents will be first-class workers. They’ll get identities, access controls, monitored, and contained. All just like human workers.

At the end of the day, it doesn’t do much good to worry about whether AI agents can be compromised. They can and they will be. Instead, ensure you have the controls in place to detect, contain, and respond when it happens. That’s how you prevent your AI agents from becoming your next insider threat.


This post was written by a human.
Hello! I’m Brian, confirming that I (a human) actually wrote this post.

Read more & connect
Join the conversation and discuss this post on LinkedIn. You can find all my human-written posts on my author page on the Citrix blog (or via RSS).

Video of my most recent talk
In May I gave the closing keynote at the EUCtech Denmark 2025 conference, called The Future of Work in an AI-Native World. I talked about a lot of what I covered today and walked through how AI will evolve and impact the workplace in the coming years. You can watch it on YouTube.

My upcoming public talks

  • AppManagEvent: Closing Keynote: AI & the Future of Enterprise Apps — Utrecht, Netherlands, Oct 10
  • MAICON 2025: AI at Work: The Employees’ Revolution! — Cleveland, Ohio, Oct 14-16

AI Computing User Agent (CUA) skills benchmark progress
We got an update since my last post, with the leading CUA now scoring 56%. (Humans score 72%.) What is this and why does it matter?