Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Artificial Intelligence - Rogue AI agents put trusted access under scrutiny
Artificial Intelligence API Security News & Analysis Security

Rogue AI agents put trusted access under scrutiny

Kirsten DoyleBy Kirsten DoyleSeptember 22, 20262 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Rogue AI agents put trusted access under scrutiny
Share
Facebook Twitter LinkedIn Email Copy Link
TL;DR (AI Generated)

Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitimate access. .

The company said agents had bypassed access controls, used exposed credentials, and reached parts of third-party services outside their intended access. .

He adds that when agentic software can operate autonomously at machine speed, APIs must move beyond simple authentication and verify both the identity and integrity of the agent software itself for every request. “We are seeing a shift where security must be enforced within the software logic, or organizations will remain vulnerable to these sophisticated agent-based threats.".

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitimate access. 

In both cases, agents were able to use valid accounts or credentials and continue searching for ways into systems and data beyond the access they had been given.

OpenAI this week disclosed more details from its continuing review of the Hugging Face incident and other unexpected activity by its models. The company said agents had bypassed access controls, used exposed credentials, and reached parts of third-party services outside their intended access. 

Separate reporting on the investigation found that agents had been probing Hugging Face as early as May, before the larger July compromise. In the July incident itself, agents found publicly exposed Hugging Face credentials and went on to chain vulnerabilities that gave them code execution on multiple servers.

Spain’s data protection authority, the AEPD, has also disclosed a separate case involving an AI agent, which it describes as the first breach notification of its kind received by the regulator. 

According to the organization that reported the incident, the agent logged into the target system and searched the application for weaknesses with limited human intervention. It found and exploited a vulnerability, modified personal data, and accessed billing information. 

The AEPD said the case remains under review and cautioned that use of a particular AI model does not mean the model or its provider was compromised or designed for malicious purposes.

Relying on account authentication alone is insufficient

Ted Miracco, CEO of Approov, says: “These incidents confirm that relying on account authentication alone is necessary but not sufficient. Whether it’s a probed vulnerability or an autonomous data breach, the fundamental issue remains: an account credential only proves who is authorized, not what software is actually behind the request.

He adds that when agentic software can operate autonomously at machine speed, APIs must move beyond simple authentication and verify both the identity and integrity of the agent software itself for every request. “We are seeing a shift where security must be enforced within the software logic, or organizations will remain vulnerable to these sophisticated agent-based threats.”

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Gemini crosses the line in cybersecurity test
  • Kirsten Doyle
    Texas utility CenterPoint confirms breach after attacker leaks customer data
  • Kirsten Doyle
    Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
  • Kirsten Doyle
    A reverse image search platform exposed more than 9 million facial images

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Gemini crosses the line in cybersecurity test

September 22, 20267 Mins Read

AI agents taking unsanctioned action during cyber testing

August 24, 20263 Mins Read

Walking the AI Security and ROI Tightrope

August 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}