Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

AI agents widen attack surface, defenders urged to red-team

Security experts say AI agents are increasingly used in attacks and introduce new risks, while a growing market offers AI-powered red teaming to help defenders.

  • Matt Hartman, former acting head of cyber at CISA, said agents will inevitably receive access to sensitive systems and data, and should be treated as privileged identities.
  • Armadin and Tenex.ai said they ran the 'largest controlled live AI cyberattack on record' over three days, generating 17 million offensive actions and 238 security findings.
  • Former NSA cyber boss Rob Joyce said organizations will be red-teamed whether they pay for it or not.

AI agents are proving highly effective at hacking organisations and are creating a new attack surface, according to security experts. Matt Hartman, former acting head of cyber at the US Cybersecurity and Infrastructure Security Agency (CISA), said agents will inevitably receive access to sensitive systems and data, and that organisations should treat every agent as a privileged identity.

Hartman also noted that AI-enabled identity and social engineering attacks are increasing significantly, with highly personalised phishing and automated reconnaissance making traditional indicators of trust less reliable. He said defenders need to focus on strong identity, phishing-resistant authentication, behavioural signals and zero-trust principles.

On the defensive side, there is a growing market for AI-native, automated red teaming and penetration testing. Former NSA cyber boss Rob Joyce said: 'You are going to be red-teamed whether you pay for it or not. The only difference is, you know who gets the results delivered to them.'

Armadin, founded by Mandiant's former CEO Kevin Mandia, builds autonomous attacker swarms that simulate real-life attacks. Ahead of Black Hat, Armadin and Tenex.ai said they executed what they called the 'largest controlled live AI cyberattack on record' for an unnamed global institution. Over three days, the swarm generated 17 million offensive actions, discovered 38 validated attack paths and produced 238 security findings. Tenex.ai triaged 101,169 alerts and reconstructed the attack across 231 billion raw events.

Armadin's chief offensive security officer Evan Peña said the exercise would have taken a five-person analyst team about 2,400 hours to complete. He argued that AI agents can cover much more attack surface because they do not sleep or take holidays, and can be pre-trained with expertise in coding, source-code review and network misconfigurations.

Why this matters: The rise of AI agents in both attacks and defences is changing the security landscape, requiring organisations to adapt their identity and red-teaming strategies.

What this means for you: Organisations may need to consider AI-powered red teaming and treat AI agents as privileged identities to keep pace with evolving threats.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.