TECH NEWS | AI agents expand enterprise cybersecurity risks

0

The warning comes during Cybersecurity Awareness Month, observed every October, as organizations increasingly deploy AI systems capable of accessing applications.

cybersecurity

The growing use of artificial intelligence is expanding cybersecurity risks beyond human users, with security experts warning that AI agents, privileged accounts and synthetic media require organizations to update existing security practices.

The warning comes during Cybersecurity Awareness Month, observed every October, as organizations increasingly deploy AI systems capable of accessing applications, retrieving information, executing workflows and making decisions.

Darren Guccione, CEO and co-founder of Keeper Security, said AI agents should be treated as digital identities because they can authenticate into systems and operate with assigned credentials and permissions.

“If an agent has credentials and permissions, it represents an identity, and every identity creates risk when its access is excessive, persistent or poorly monitored,” Guccione said.

He said the scale of AI deployment presents an additional challenge because organizations can create hundreds or thousands of nonhuman identities more quickly than they can onboard human employees.

Guccione recommended applying zero-trust principles to AI agents, including verifying identities, enforcing least privilege, eliminating unnecessary standing access, monitoring privileged activity and protecting and rotating credentials and secrets.

“Cybersecurity awareness must evolve alongside technology,” he said. “We have spent years teaching organizations that every employee identity requires governance. Now we need to extend that understanding to machines.”

Privileged access expands

Michael Marino, senior vice president of strategy for identity security at Keeper Security, said the traditional role of privileged access management has expanded as organizations move beyond on-premises infrastructure and adopt cloud, hybrid and remote environments.

He said privileged access management was historically focused on securing administrator passwords and maintaining audit trails. The expansion of access across employees, contractors, applications, service accounts and automated systems has broadened the scope of privilege.

“Modern PAM, therefore, has to be about much more than protecting passwords,” Marino said. “It must control when privileged access is granted, what someone or something can access and what happens during that session.”

Keeper research cited by Marino found that 94% of organizations operate in hybrid or cloud-first environments.

Marino said least privilege, just-in-time access and zero standing privilege can help organizations replace persistent administrative rights with temporary and auditable access.

He also pointed to AI as both a source of new risk and a potential security tool, saying AI agents and other nonhuman identities are creating privileged access at a scale that security teams cannot manage manually, while AI can help analyze activity and identify suspicious behavior.

Deepfakes add personal risks

Anne Cutler, a cybersecurity expert at Keeper Security, focused on the growing use of deepfakes in social engineering attacks.

She said synthetic media can allow attackers to imitate a person’s voice, appearance or communication style and make fraudulent requests appear more credible.

“Cybersecurity Awareness Month is an opportunity to update the way we think about personal security,” Cutler said. “Recognizing phishing emails remains important, but awareness now also means questioning unexpected requests regardless of how authentic or personal they appear.”

Cutler advised people to verify unusual or urgent requests through another trusted channel and avoid providing passwords or multifactor authentication codes in response to unsolicited messages.

“A familiar face or voice should no longer be treated as proof of identity,” she said.

She said awareness of deepfakes should now be considered part of personal cybersecurity as synthetic media becomes more accessible to cybercriminals.


Full disclosure: All news articles published on the TechSabado website are written by human journalists, unless otherwise specified. Final text editing is also performed by human editors, with artificial intelligence (AI) used only to assist with additional grammar and style guide corrections..


————————————————————————-
TEN YEARS OF TECHSABADO!


PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE & SPOTIFY channels.



WATCH TECHSABADO ON OUR YOUTUBE CHANNEL:












WE ARE ALSO ON SPOTIFY



WATCH OUR OTHER YOUTUBE CHANNELS:




PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.

roborter
by TechSabado.com editors
Tech News Website at  | Website

Leave a Reply

Your email address will not be published. Required fields are marked *