惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
L
LINUX DO - 最新话题
T
Troy Hunt's Blog
博客园_首页
量子位
Jina AI
Jina AI
S
SegmentFault 最新的问题
IT之家
IT之家
Hacker News - Newest:
Hacker News - Newest: "LLM"
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
S
Securelist
Google Online Security Blog
Google Online Security Blog
P
Privacy International News Feed
博客园 - Franky
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
NISL@THU
NISL@THU
C
Cisco Blogs
V
Vulnerabilities – Threatpost
腾讯CDC
The Hacker News
The Hacker News
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
Webroot Blog
Webroot Blog
The Register - Security
The Register - Security
Scott Helme
Scott Helme
B
Blog
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
W
WeLiveSecurity
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tenable Blog
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Schneier on Security

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
The Importance Of Red Teaming For Scaling Enterprise AI Agents
Joan Vendrel · 2026-05-22 · via Forbes - Innovation

Joan Vendrell, NeuralTrust CEO and cofounder, has 15+ years of technology leadership experience advancing enterprise-grade AI security.

getty

​I recently spoke with a CISO who was preparing for a major production rollout of an autonomous customer service agent. They had passed their traditional penetration tests with flying colors. But when I asked how the agent would handle a multi-step prompt injection attack that evolved in real time, there was a long silence. "We tested the model last month," they finally said. "But the agent is learning and interacting with live data every hour."

This is the fundamental challenge of the agentic era. Traditional security testing is a snapshot in time, while agentic AI is a continuous movie. At a time when agents are being granted the authority to execute workflows, call APIs and access sensitive databases, relying on a "one-and-done" security audit is like checking the locks on a house while the walls are still being built.

We are seeing a shift where the attack surface is not just the code or the network, but the reasoning process itself. If we don't move toward a model of continuous red teaming, we aren't just leaving the door open; we are handing the keys to the house to an autonomous operator we haven't fully vetted.

The Problem: The Dynamic Attack Surface And "Adversarial Reasoning"

The core issue is that AI agents are non-deterministic. Unlike a standard application where input A always leads to output B, an agent’s behavior changes based on its context, its memory and the tools it has access to. This creates a playground for what I call "adversarial reasoning": attacks designed to corrupt the agent's logic rather than just its input.

Gartner predicts that by 2028, more than 50% of enterprises will use dedicated AI security platforms to manage these risks. The reason is simple: the OWASP Top 10 for LLM Applications has evolved. We aren’t just worried about simple prompt injections. We are now facing "agentic hijacking" and "indirect prompt injection," where an agent is manipulated through the very data it is supposed to analyze.

In my experience, traditional red teaming—where a human team spends two weeks trying to break a system—cannot keep up with the speed of AI development. We need a "machine-versus-machine" approach to security.

5 Steps To Implementing Continuous Red Teaming

To secure the agentic enterprise, we must move beyond static testing and embrace a proactive, continuous defense. Here are five steps I believe every security leader should take.

​1. Automate the adversary with attacker agents.

If your agents are operating 24/7, your red teaming must do the same. You need to deploy adversarial agents with the sole job of finding weaknesses in your production agents.

This is about stress-testing the agent’s reasoning. Can it be tricked into bypassing a safety guardrail? Can it be convinced to escalate its own privileges? By using the MITRE ATLAS framework to map these attacks, you can automate the discovery of vulnerabilities before a malicious actor does.

​2. Stress-test the tool-use and API boundaries​.

The most dangerous part of an AI agent isn't the model, but the tools it can call. Red teaming must focus heavily on "insecure output handling," a top risk in the OWASP 2025 list.

You need to simulate scenarios where an agent is given a malicious command through a trusted tool, such as a compromised email or a poisoned database entry. Can an agent be tricked into executing a "delete" command on a database because it "reasoned" it was the right thing to do? Testing these boundaries is the new frontier of security.

​3. Align with the NIST AI risk management framework.

​The NIST AI RMF provides a critical taxonomy for managing AI risk. In my view, continuous red teaming should be mapped directly to the NIST "Measure" and "Manage" functions. This ensures that your testing isn't just a series of random attacks, but a structured validation of your risk tolerance.

By using a standardized framework, you can provide the board with measurable data on your AI security posture, moving from "we think we're safe" to "we know we're resilient."

​4. Simulate indirect prompt injection scenarios.

​One of the most insidious threats today is indirect injection. Imagine an agent reading a public website to summarize news, only to find a hidden instruction in the HTML that tells it to exfiltrate the user's session cookie. Your red team must continuously feed your agents "poisoned" data to see if they can maintain their instructions.

In my experience, the best defense is a zero-trust approach to agent inputs. Never assume the data an agent retrieves is safe.

​5. Focus on "identity lineage" during attacks.

​During a red team exercise, pay close attention to how the agent’s identity is used. Does the agent maintain a clear chain of accountability when it’s under pressure? If an adversarial prompt tricks an agent into performing an unauthorized action, can you still trace that action back to the original human intent?

Continuous red teaming should validate that your identity lineage remains unbroken, even when the agent’s reasoning is compromised.

The Bottom Line: Security Is A Living Process

The rise of agentic AI is the most significant shift in enterprise technology in a generation, but it requires a new level of discipline. We cannot secure autonomous systems with manual, point-in-time processes.

In my experience, the companies that will lead the next decade are those that treat security not as a hurdle to be cleared, but as a living, breathing process. By embracing continuous red teaming, we don't just find vulnerabilities; we build the resilience necessary to let our AI agents move faster, do more and transform our businesses with confidence.​​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?