LIVE · cybersecurity feed
Live wire
ai

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

A new report highlights a significant blind spot in enterprise security architectures concerning the proliferation of third-party AI agents. The forthcoming 2026 State of Agent Security Report indicates that current security models, often designed to protect AI systems directly chosen and deployed by an organization, frequently fail to account for AI capabilities embedded within third-party…

ZeroDay News ·

Source: The Hacker News

A new report highlights a significant blind spot in enterprise security architectures concerning the proliferation of third-party AI agents. The forthcoming 2026 State of Agent Security Report indicates that current security models, often designed to protect AI systems directly chosen and deployed by an organization, frequently fail to account for AI capabilities embedded within third-party products that operate outside the purview of traditional identity and access management (IAM) infrastructure.

The report's findings reveal that a substantial number of third-party products now incorporate AI functionalities. Specifically, approximately 1,280 such products were identified as embedding AI in the environments studied. A notable portion of these, around 282, are integrated with enterprise single sign-on (SSO) systems. This integration typically means their access and user authentication can be managed and monitored through existing identity infrastructure, providing a degree of visibility and control.

However, the vast majority of these AI-enabled third-party products, roughly 1,000 according to the report, operate without authenticating through the organization's primary identity stack. This lack of integration means they are effectively "invisible" to security teams relying on IAM systems to govern access and enforce policies. The issue is not one of deliberate concealment, but rather a fundamental limitation: an identity infrastructure can only manage and secure what authenticates through it.

This gap presents a considerable challenge for enterprise security. Third-party agents, even those embedded in seemingly innocuous applications, can access, process, and potentially exfiltrate sensitive data. Without proper authentication and authorization mechanisms tied to the enterprise's identity infrastructure, these agents operate with an unknown security posture and an unmanaged risk profile. This class of issue typically means that traditional security controls like multi-factor authentication, session monitoring, and access revocation may not apply.

Mitigation for this class of problem commonly involves a comprehensive discovery process to identify all third-party applications and services in use, followed by a thorough assessment of their embedded AI capabilities and data access requirements. Organizations are often advised to implement robust third-party risk management programs, including contractual agreements that mandate specific security controls and audit rights. Technical solutions might include network segmentation, API security gateways, and specialized agent security platforms designed to monitor and control the behavior of AI agents regardless of their authentication path.

The emergence of AI as an embedded feature across a wide array of third-party products underscores a broader trend in enterprise technology: the decentralization of advanced capabilities. As AI becomes a ubiquitous component rather than a standalone system, security strategies must evolve beyond protecting explicitly deployed AI models to encompass the pervasive and often unmanaged AI agents operating within the digital supply chain. This shift necessitates a re-evaluation of how organizations discover, assess, and secure all forms of intelligent automation interacting with their data and systems.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

AI SPERA, the company behind the cyber threat intelligence platform Criminal IP, has announced AITEM (AI-Powered Threat Exposure Management), an expansion of its Attack Surface Management (ASM) offerings. AITEM aims to move beyond traditional asset discovery to provide a more comprehensive approach to understanding, prioritizing, and responding to security exposures. The platform is scheduled…

ai

AI Is Getting Really Good at Messing With Cybercriminals

Anti-cybercrime initiatives are increasingly deploying artificial intelligence to disrupt scammers by engaging them with lifelike bots, which the criminals mistake for genuine victims. This strategy aims to waste scammers' time and resources while gathering intelligence on their operations.

security

Canadian cybersecurity executive arrested in federal extortion case

A Canadian cybersecurity executive was arrested in Pennsylvania on Thursday, facing federal charges of conspiracy to commit extortion. Edward Dubrovsky, 54, a co-founder and former Chief Operating Officer of CYPFER, a firm specializing in ransomware negotiation, is charged with conspiring to threaten the confidentiality of information for extortion and conspiring to commit Hobbs Act extortion,…

ransomware

FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe

The Federal Bureau of Investigation (FBI) has reportedly arrested Edward Dubrovsky, a co-founder of the ransomware negotiation firm Cypfer and currently associated with CyberSteward. The arrest is said to be part of the ongoing ShinyHunters investigation, specifically in connection with an incident involving FBI job applicant data.

security

Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

A former core infrastructure engineer has been sentenced to prison for an attempted cyber extortion plot against an industrial firm. The engineer reportedly deleted administrative accounts and reset hundreds of user passwords, subsequently demanding a ransom of 20 Bitcoin to prevent further disruption to the company's servers.

ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…