ZeroHour

Search: “ai-agent”

6 stories

Exaforce extends its AI security tool to monitor more than just Claude

Exaforce AI Security extends beyond Claude to monitor OpenAI, Gemini, and Copilot agents using existing SOC telemetry, no new endpoint agents.

Exaforce expanded its June Claude Compliance API integration into Exaforce AI Security, adding monitoring for OpenAI, Gemini, Microsoft Copilot, and OAuth-connected AI apps. The tool inventories AI agents by correlating EDR, cloud, SaaS, and model-provider logs without new gateways or endpoint agents, and can respond by revoking sessions, deactivating API keys, isolating devices, or killing agent processes via existing controls. Analysts note the agentless approach lowers friction but lacks runtime inspection and inline blocking offered by competitors such as Palo Alto Prisma AIRS, SentinelOne Prompt AI Agent Security, and CrowdStrike Falcon Guardian. A March 2026 Cloud Security Alliance survey found 68% of organizations cannot distinguish human from AI-agent activity and 74% report AI agents receive excessive access.

CSO Online · 1d agoTools

New infosec products of the week: September 11, 2026

Weekly product roundup: Securin Platform GA, Orchid Security AI-agent identity controls, Akeyless Agentic Runtime Authority, and Scytale AI-powered TPRM.

Help Net Security's weekly product roundup highlights four vendor launches. Securin announced general availability of its AI-native Preemptive Exposure Management platform combining attack surface discovery, vulnerability intelligence, offensive validation and remediation. Orchid Security added identity drift detection and application-level kill switches targeting AI agents that escalate privileges via hard-coded credentials, orphaned accounts and excessive permissions. Akeyless released Agentic Runtime Authority, a real-time intent-based access control layer on top of its SecretlessAI credential protection, and Scytale launched AI-powered third-party risk management features in its Vendors module.

Help Net Security · 6d agoTools

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild

The hardest part of agentic AI may be rebuilding the business

Deloitte survey finds most organizations' business processes and workforces unprepared for agentic AI adoption.

Deloitte research reports that only 16% of leaders say their business processes are ready for agentic AI, with 46% reporting readiness even among organizations that have deployed agents at scale. Key blockers include fragmented data foundations, limited trust and governance, and integration cost and complexity. About 43% of leaders expect significant job disruption within 12 to 18 months, while 71% report providing baseline AI-agent literacy training. Roughly 31% expect at least half of business processes redesigned around agents within two years, rising to 74% within four years.

Help Net Security · Aug 14, 2026AI industry