generative AI for data analysis

Autonomous SOC agents turn AI breaches into direct firewall access.

In 2025, adversaries exploited vulnerabilities in AI security tools across more than 90 organizations, gaining unauthorized access to sensitive data and cryptocurrency.

4 min readVentureBeat
Autonomous SOC agents turn AI breaches into direct firewall access.

The autonomous SOC agents shipping now are the first AI tools that can act on the network, not just read from it, and that changes the threat model faster than most security teams are prepared to absorb. In 2025, adversaries compromised AI tools at more than 90 organizations by injecting malicious prompts into legitimate applications. Those tools could read data and steal credentials, but they could not touch a firewall rule or modify an IAM policy. The agents deploying today can do all of that and more, with their own privileged credentials, through approved API calls that endpoint detection classifies as authorized activity. The adversary never touches the network because the agent does the work for them. That is not a theoretical escalation. It is the difference between a tool that leaks and a tool that obeys.

The governance gap is not abstract, and it is not waiting for a future incident. OWASP's Top 10 for Agentic Applications, built with more than 100 security researchers, documents exactly how these systems fail: goal hijacking, tool misuse, and identity abuse are not edge cases but the expected failure modes when agents ship with write access. The Saviynt report found that 86% of organizations do not enforce access policies for AI identities, and only 5% of CISOs feel confident they could contain a compromised agent. Palo Alto Networks measured an 82:1 machine-to-human identity ratio in the average enterprise. Every autonomous agent added to production extends that gap, and the industry is shipping them faster than the controls designed to contain them. Cisco is adding inspection at the network layer, and Ivanti built policy enforcement, approval gates, and data context validation into its platform at launch. Both approaches are necessary, but neither is sufficient on its own. The question is not whether the controls will arrive. It is whether they arrive before the first production compromise turns a read-only breach into a full infrastructure takeover.

The practical takeaway for security leaders is not to avoid autonomous agents but to audit them with the same rigor applied to any privileged identity. Run the ten-question OWASP audit against every agent with write access to production infrastructure within the next 30 days. Ask which agents accept external inputs without validation, which execute irreversible actions without human approval, and which inherit user credentials instead of scoped agent identities. If the answer to any of those questions is "I don't know," that tool does not ship to production until it does. The agents that ship with governance built in, like Ivanti's Continuous Compliance and Neurons self-service agent, will have clear answers to every question. The ones that do not will be the ones that make the 2025 compromise count look like a warm-up.

The board conversation is three sentences, and it should be delivered without hedging. Adversaries compromised AI tools at more than 90 organizations in 2025. The autonomous tools deploying now have more privilege than the ones that were compromised. The organization has audited every autonomous tool against OWASP's ten risk categories and confirmed that the governance controls are in place. If that third sentence is not true, it needs to be true before the next agent ships. The window between a tool that reads data and an agent that rewrites infrastructure is measured in months, not years. The controls have to ship in that same window, or the first agentic breach will not be a headline. It will be a postmortem.

From VentureBeat

Adversaries injected malicious prompts into legitimate AI tools at more than 90 organizations in 2025, stealing credentials and cryptocurrency. Every one of those compromised tools could read data, and none of them could rewrite a firewall rule.

The autonomous SOC agents shipping now can. That escalation, from compromised tools that read data to autonomous agents that rewrite infrastructure, has not been exploited in production at scale yet. But the architectural conditions for it are shipping faster than the governance designed to prevent it.

Read the original at VentureBeat