
Cisco researchers found that attackers exploiting AI models across multiple conversation turns succeeded 88.3% of the time against 15 flagship models, a threat that single-turn security testing routinely misses. A VentureBeat survey shows more than half of enterprises have already experienced confirmed AI agent security incidents or near-misses, yet most still lack basic protections like scoped identities or sandboxing—leaving them exposed to the adaptive attacks Cisco warned about.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Cisco tested 6,986 multi-turn attacks (where attackers adapt their strategy across multiple conversation turns) against 15 flagship AI models and found attackers succeeded 88.3% of the time. Single-turn red-teaming—the current industry standard—missed these breakthroughs, Cisco's head of AI threat intelligence Amy Chang warned at VB Transform 2026.
Why it matters
A June 2026 VentureBeat survey of 107 enterprise respondents found 54% have already suffered a confirmed AI agent security incident (18%) or caught a near-miss (36%). Yet most companies rely on outdated defenses: only 32% assign each agent its own scoped identity, only 30% isolate high-risk agents in sandboxes, and 82% depend primarily on provider-native or hyperscaler controls—tools not designed to stop adaptive multi-turn attacks.
What to watch
Major security vendors are moving quickly. Palo Alto Networks closed its $25 billion(約4兆円) acquisition of CyberArk in February, and CrowdStrike has also entered the space—signaling that enterprise AI agent security is becoming a boardroom priority and a major M&A driver.
When Cisco researchers set out to stress-test AI agent security, they ran 6,986 multi-turn attacks against 15 flagship models in a controlled environment. The results were stark: attackers who adapted their prompts across multiple conversation turns broke through 88.3% of the time. This finding, presented by Amy Chang, Cisco's head of AI threat intelligence and security research, at the agentic security panel at VB Transform 2026, revealed a blind spot in how the industry currently validates AI defenses. Most red-teaming today focuses on single-turn attacks—one-shot prompts that test whether a model can be tricked in isolation—and Cisco's data showed that this approach systematically misses the sophisticated, iterative attacks that adversaries employ in practice.
The threat is no longer theoretical. In June 2026, VentureBeat conducted a survey of 107 enterprise respondents that painted a picture of widespread vulnerability. More than half of enterprises, 54%, have already experienced either a confirmed agent security incident (18%) or a near-miss that was caught before damage occurred (36%). The survey also revealed how thin current defenses are: just 32% of companies give every agent its own scoped, managed identity, and only 30% isolate their highest-risk agents in sandboxes. The vast majority, 82%, rely on provider-native controls and hyperscaler-provided security tools as their primary defense layer—the same vendors that built those tools for traditional workloads, not for adaptive, multi-turn interactions in AI agents.
The security industry has taken note. Palo Alto Networks closed its $25 billion(約4兆円) acquisition of CyberArk in February, and CrowdStrike has also moved into the AI agent security space. These blockbuster deals signal that enterprise leaders now view AI agent security as mission-critical, and that vendors who cannot address multi-turn attack scenarios risk being displaced by those who can. For organizations still running single-turn red-teaming programs, Cisco's message is clear: you are not seeing the attacks that matter.
Cisco's findings expose a critical gap between how enterprises currently test AI agent security and the real-world threat landscape. Multi-turn attacks—where an attacker refines their approach based on earlier model responses within a single conversation—represent a fundamentally different threat from the isolated, single-turn prompts that dominate today's red-teaming practices. An 88.3% success rate across 15 flagship models suggests that current defenses are not equipped to handle adaptive adversaries who operate at conversation depth.
The VentureBeat survey data reinforces the urgency: 54% of enterprises have already experienced either confirmed incidents or caught near-misses, yet the majority rely on control layers—provider-native tools and hyperscaler defenses—that were not designed with multi-turn agent interactions in mind. The low adoption of scoped identities (32%) and agent isolation via sandboxing (30%) indicates that most organizations are still treating AI agent security as a binary access problem rather than a behavioral containment challenge. This mismatch between threat sophistication and defensive posture has not gone unnoticed by the security vendor ecosystem, as evidenced by high-value M&A activity: Palo Alto Networks' $25 billion(約4兆円) acquisition of CyberArk in February signals that enterprise customers expect their security platforms to address AI-specific risks as a core capability.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
1 minute a day. The AI essentials.
200+ sources · Email / LINE / Slack