AIToday
AI Coding AssistantsAI Regulation & PolicyVentureBeat AIPublished: Apr 21, 2026, 22:00 JST1 min read

Autonomous AI security agents now have write access to firewalls — a dangerous escalation from read-only compromises at 90+ organizations in 2025

3 Key Points

  1. Hackers injected malicious prompts into legitimate AI security tools at more than 90 organizations during 2025, stealing credentials and cryptocurrency. Until now, these compromised tools could only read data from networks. Cisco announced AgenticOps for Security in February with a new capability: autonomous agents that can rewrite firewall rules and modify access policies on their own.

  2. The shift is dangerous because a compromised AI agent can use its own legitimate, pre-approved credentials to bypass your firewall, change who can access what systems, or lock down computers — all while security monitoring systems see these as authorized actions. The attacker's hands never touch your network; the AI agent does the damage for them.

  3. If your organization uses these new autonomous security agents, a successful attack on the agent itself becomes an attack on your entire infrastructure — not just data theft, but the ability to rewrite the rules that protect you. The governance and safeguards to prevent this are being built slower than the tools themselves are shipping to customers.

Ask the AI about this article →

VentureBeat AIRead Original Article

Get the latest AI Coding Assistants news every morning

For example, today's edition would include:

  • GitHub Copilot cuts AI coding costs without hurting qualityGitHub Copilot Blog · 2h ago
  • GitHub Copilot cuts AI coding costs without hurting qualityGitHub Blog (AI) · 2h ago
  • AWS AgentCore auto-generates architecture docsAmazon AI Blog · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAI-generated fake women are being used to scam money from men online—exposing a gap in platform defenses