Hackers injected malicious prompts into legitimate AI security tools at more than 90 organizations during 2025, stealing credentials and cryptocurrency. Until now, these compromised tools could only read data from networks. Cisco announced AgenticOps for Security in February with a new capability: autonomous agents that can rewrite firewall rules and modify access policies on their own.
The shift is dangerous because a compromised AI agent can use its own legitimate, pre-approved credentials to bypass your firewall, change who can access what systems, or lock down computers — all while security monitoring systems see these as authorized actions. The attacker's hands never touch your network; the AI agent does the damage for them.
If your organization uses these new autonomous security agents, a successful attack on the agent itself becomes an attack on your entire infrastructure — not just data theft, but the ability to rewrite the rules that protect you. The governance and safeguards to prevent this are being built slower than the tools themselves are shipping to customers.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
GitHub's podcast episode and a guide explain new AI-related terms in software development, including loop engi…

Google released Gemini 3.8 Flash, its third Flash model in six weeks

Protect Democracy sued four federal agencies to force disclosure of the Trump administration's classified revi…

The US Department of Justice has sided with AI companies in a copyright lawsuit brought by the New York Times…

Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels announced a one-year moratorium on student-facing ge…

GitHub shared four efficiency upgrades for its AI coding agent Copilot
