19 Sources
[1]
CrowdStrike unveils coordinated multi-agent investigations across five domains
The company has announced coordinated multi-agent investigations across endpoint, identity, SaaS, cloud and network, with autonomy levels customers set per workflow, but the NIS2 directive runs its 24-hour early warning from the moment an entity becomes aware and makes the management body
[2]
Overcoming the biggest blocker to AI production
Legacy security models stall AI agents. We need unified, zero-anonymity identity Autonomous AI agents are already running inside core infrastructure - executing code, applying policies, and managing DevOps functions. And the projects keep stalling, because the security models they're being wired
[3]
Box's approach to AI agent security | VentureBeat
Identity and permissions are no longer enough to secure enterprise AI agents. They govern what an agent can reach, not how it behaves once it starts working on its own, and an autonomous agent can turn legitimate access of enterprise data into unintended action in seconds. That gap is pushing
[4]
AI agents need their own identity before they need a gateway
Enterprise AI has entered a new era. Organizations are rapidly moving beyond assistants that answer questions to autonomous agents capable of reasoning, invoking tools, accessing enterprise applications, coordinating with other agents, and completing multi-step business workflows with minimal human
[5]
Agentic Identity Provider arrives at CrowdStrike Fal.Con
CrowdStrike builds an identity provider for AI agents, not humans Every enterprise identity system ever built started with a human logging in. AI agents don't work that way: there's no face behind the login, no single owner, and soon there will be far more of them than there are people to watch
[6]
AI agents that pass authentication can still drift, expose data, or get memory-poisoned
There is a clear repeating trend in agent deployments: The gateway is the first control teams reach for, but it is the one they are least ready to run. This is because gateways sit on top of identity and attribution layers that are mostly not there. The first layer of risk is not hypothetical. In
[7]
CrowdStrike gives AI agents an identity provider, parallel SOC investigations and package blocking
CrowdStrike gives AI agents an identity provider, parallel SOC investigations and package blocking CrowdStrike Holdings Inc. today announced three additions to its Falcon platform: an identity provider built for artificial intelligence agents, a rebuilt investigation layer that runs multiple
[8]
Continuous AI agent identity becomes a 24/7 job at Fal.Con
Continuous identity becomes the new front line for AI agents: theCUBE's Fal.Con 2026 day two keynote analysis Identity security has always worked the same way: log in once, get trusted until you log out. That model breaks down the moment an AI agent does the logging in, since an agent can call a
[9]
AI control plane emerges as George Kurtz details SafeMind
George Kurtz says the AI control plane is CrowdStrike's next security frontier The AI control plane is emerging as the next contested layer of enterprise security, as autonomous agents spread across endpoints, cloud workloads and identity systems faster than most organizations can inventory them.
[10]
CrowdStrike Unveils the Next Evolution of the Agentic SOC
Autonomous attacks move across systems at machine speed - only CrowdStrike can investigate every domain simultaneously CrowdStrike unveiled the next evolution of the agentic SOC. AI agents execute attack actions across multiple systems at machine speed. The investigation has to move the same way.
[11]
Defending Enterprise Applications Against Agent-Era Threats
Join the DZone community and get the full member experience. Join For Free The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real privileges, such as updating databases, calling microservices,
[12]
AWS CrowdStrike partnership takes on agentic AI threats
Security becomes a shared job as AI widens the attack surface Cloud providers and security companies are being pulled into tighter formation as artificial intelligence widens the enterprise attack surface faster than any single supplier can cover it. The AWS CrowdStrike partnership is one of the
[13]
Introducing the CrowdStrike Agentic Identity Provider, the Foundation for AI Agent Identity Security
CrowdStrike's Agentic IdP creates trusted identities for AI agents, accelerating the shift to Continuous Identity CrowdStrike introduced the CrowdStrike Agentic Identity Provider (Agentic IdP), establishing Falcon Next-Gen Identity Security as the identity control plane for the agentic enterprise
[14]
Stopping the AI Agent Actions No Rule Could See Coming
Check Point introduces a new class of contextual AI protection that understands an agent's full context, intent and behavior across multiple steps, and prevents harmful actions before they execute. AI agents are already operating inside the enterprise. Coding agents write and execute code,
[15]
AI detection and response emerges as a security category
The AI edge that helps defenders is helping attackers just as much Enterprise security is reorganizing around AI detection and response, as autonomous agents move from pilot projects into production systems that can act, chain tasks together and improvise. The same capabilities that make agents
[16]
Agentic AI attack surface shifts security to machine speed
When agents move at machine speed, security teams lose their lag time The agentic AI attack surface is less a matter of new territory than of new velocity, as autonomous software now reads, writes and moves corporate content faster than any human adversary could. That shift is forcing security
[17]
AI security debt exposed as adversarial AI finds old flaws
Adversarial AI forces enterprises to confront decades of dormant security debt Enterprise AI security has entered a phase unlike any previous technology cycle, as frontier models surface software flaws that went unnoticed for decades. The result is a threat landscape expanding in two directions at
[18]
Agentic AI security: when trusted agents become the risk
Delegated authority turns the trusted AI agent into the security problem Enterprise defenses hunt the unauthorized: the foreign file, the stolen credential, the behavior nobody sanctioned. Agentic AI security inverts that model, because the agent moving through the business was invited in and
[19]
Four safeguards to stop your AI agents from going rogue
Artificial intelligence agents are moving from experimentation to production, and with this shift, the stakes are rising. A coding agent at PocketOS recently deleted an entire production database. An agent at Meta exposed sensitive user data for two hours. An Instagram support chatbot allowed
Share
Copy Link
CrowdStrike unveiled its Agentic Identity Provider at Fal.Con, addressing a critical gap as enterprises deploy roughly 90 AI agents per employee. Legacy identity and access management systems built for humans can't secure autonomous agents that execute thousands of actions across infrastructure in seconds, forcing a fundamental shift in how organizations think about identity management.
CrowdStrike has launched an Agentic Identity Provider at its Fal.Con conference, addressing a fundamental mismatch between legacy identity systems and the reality of AI agents operating at machine speed
5
. The announcement comes as enterprises face a stark ratio: roughly 90 AI agents for every human employee, according to Jennifer "JJ" Johnson, chief marketing officer at CrowdStrike5
. Every enterprise identity system ever built started with a human logging in, but AI agents don't work that way—there's no face behind the login, no single owner, and soon there will be far more of them than people to watch over them.
Source: SiliconANGLE
The Agentic Identity Provider fills a gap in CrowdStrike's Continuous Identity system, which uses technology from its $740 million acquisition of SGNL Inc.
5
. While Continuous Identity decides whether an agent should be allowed to do something at a given moment, the new provider handles the step before that: establishing what the agent actually is. Most companies currently stand in for agent identity using service accounts and API keys, a workaround that creates security blind spots across infrastructure.Identity and access management systems were built for a world with two kinds of actors—humans and machines—but autonomous AI agents represent a third category that existing tools cannot adequately secure
2
. Trying to fit agentic AI into outdated systems makes each agent a potential source of compromise, one that can execute thousands of actions across infrastructure in seconds. The security risks of AI agents became starkly clear when an agent deleted a company's entire production database and its backups in nine seconds2
.Source: DZone
The problem stems from how differently AI agents behave compared to the actors legacy systems were designed to govern. Humans are trackable, they log in and log out, and they operate slowly enough that visibility gaps rarely turn into immediate incidents
2
. AI agents, however, are error-prone and non-deterministic like humans but operate at machine speed, 24/7. When teams grant agents broad privileges and treat them as any other microservice, they create catastrophic risk.Identity and permissions govern what an agent can reach, not how it behaves once it starts working on its own, and an autonomous agent can turn legitimate access of enterprise data into unintended action in seconds, according to Heather Ceylan, chief information security officer at Box
3
. Access controls and permissions remain the foundation, but they were designed for humans operating in a slower, more forgiving world. A human employee with lingering permissions to a decade-old folder will rarely go looking for data inside it, but an agent will explore all of its permissions, surfacing forgotten misconfigurations and stale permissions far faster than a human ever could.The shift from governing access to governing execution represents a fundamental change in AI security. An employee with access to payroll data could be instructed to pull payroll records and write them to a public shared folder, publishing the entire company's compensation in a single move
3
. Every access check passed, but the behavior still has catastrophic consequences. Prompts alone can't reliably govern agent behavior because instructions can change, agents can absorb injected instructions, or they can be steered by files they read along the way.Authentication establishes identity, not trust, and this distinction becomes critical with AI agents that continuously reason, interpret objectives, invoke tools, and adapt behavior based on new context
4
. An AI agent may legitimately authenticate using an enterprise identity, receive valid API credentials, and be granted access to systems like Microsoft 365, ServiceNow, Salesforce, or GitHub. From an identity perspective, everything appears correct. The real challenge begins after authentication: security teams must determine whether those actions remain aligned with the user's intent and organizational policy.
Source: VentureBeat
Runtime trust extends security beyond authentication by continuously validating AI behavior throughout execution
4
. Rather than assuming authenticated agents will behave correctly, runtime trust monitors what agents actually do. This approach addresses threats like goal drift, where an agent begins with a legitimate objective but gradually deviates from the user's original intent, and excessive tool invocation, where autonomous agents with access to numerous enterprise tools call unnecessary APIs or perform administrative actions simply because the model believes those actions are useful.CrowdStrike announced coordinated multi-agent investigations across endpoint, identity, SaaS, cloud and network, with autonomy levels customers set per workflow
1
. AI agents now run attacks across several systems at once, and investigations have to move the same way, according to the company. Agents run in parallel on a shared context layer, a persistent memory across every agent, investigation and tenant. Customers set the autonomy per workflow, from human-in-the-loop approval to fully autonomous execution.Michael Sentonas, CrowdStrike's president, framed the development as addressing a trust problem. Agents in the SOC are table stakes, he said, and the question every CISO is asking is how to trust what the agents found
1
. The claim is speed, turning hours into minutes. Johnson emphasized that defending AI with AI at machine speed means getting visibility and looking cross-domain while acting simultaneously5
.Related Stories
In Europe, the speed of AI-driven security carries additional implications under the NIS2 directive, which gives essential and important entities 24 hours to file an early warning and 72 hours for full notification
1
. The clock runs from becoming aware of a significant incident, not from the moment an analyst finishes writing the incident up. Compressing the investigation with AI agents compresses the window—an agent converging on a verdict in minutes moves the moment of awareness earlier and leaves less of the 24 hours, not more.Article 20 of the NIS2 directive requires management bodies to approve the cybersecurity risk-management measures and oversee their implementation, and they can be held liable for infringements
1
. There is no autonomy slider for that responsibility. A board can approve fully autonomous execution and still owns the outcome of every action taken under it. Automating the analyst does not automate the person the directive names.To remove anonymity from infrastructure, enterprises must give every actor—spanning humans, machines, workloads, and AI agents—first-class identities, cryptographically secured by a hardware root of trust
2
. Eradicating API keys and passwords eliminates the credential sprawl that causes breaches, as well as the threat of secrets being stolen or handed over to the wrong actors. With identity rooted in real-world factors, attackers cannot impersonate a trusted machine and trick an agent into exfiltrating a database.
Source: TechRadar
AI agents, like all other actors, need to adhere to zero-trust principles. This can only happen when siloed systems are replaced by an infrastructure layer in which agents have the exact same identity type as the machines they run on and the humans who authorize them
2
. Agents should operate with short-lived privileges tied directly to specific actions authorized by a human user. Privilege attached to the action, not the actor. For example, an agent generating code must inherit its mandate from a human owner with matching authority, restricting privileges to only the specific data tables required for that task.Summarized by
Navi
[2]
[3]
[4]
[5]
16 Jun 2026•Technology

02 Sept 2026•Technology

17 Sept 2025•Technology

1
Technology

2
Technology

3
Science and Research
