Topic

AI agent security

Every THE D[AI]LY BRIEF article on AI agent security — enterprise AI analysis, benchmarks, vendor comparisons, and ROI frameworks for technology and business leaders. Updated as new coverage publishes.

encrypted reasoning

182 Credentials Hid in 'Encrypted' Reasoning. Go Rotate.

Researchers decoded 315,320 encrypted reasoning blocks from 6,708 agent trajectories published to GitHub and Hugging Face, recovering 182 credentials and 367 PII artifacts. 64 of the 704 artifacts recovered from genuine user sessions never appeared in the visible chat history, which means transcript review provably misses some of what you have already published.

August 12, 2026 · 15 min read
Amazon Bedrock AgentCore

AWS Agents Run 14 Days. The Session Is the Only Wall.

AgentCore's new Instances compute type runs agents on EC2 in your own account for up to 14 days. AWS's documentation states that agents sharing an instance get no security boundary, that the platform does not verify a session ID belongs to the caller, and that the billable instances are hidden from your EC2 console by default.

August 11, 2026 · 13 min read
AI agent security

88% Had AI Agent Breaches. 82% Think They're Protected.

Five independent research teams surveying 6,650+ enterprise leaders arrived at the same conclusion: the AI agent security crisis is measured, quantified, and widely ignored. AvePoint found 88.4% of organizations had AI agent security incidents. The Economist Enterprise study pushed it to 98%. Yet 82% of executives believe their policies protect them. Here's the confidence gap assessment and governance maturity model every CISO needs this quarter.

July 1, 2026 · 16 min read
non-human identity

9 in 10 Enterprises Breached Through Identity No One Manages

Machine identities outnumber humans 109:1 in the average enterprise, yet 57% of that identity estate is invisible to existing IAM tools. Palo Alto Networks surveyed 2,900 cybersecurity decision-makers and found 9 out of 10 organizations experienced identity-related breaches in the past year. AI agents are making the crisis exponentially worse — they discover and exploit ungoverned credential paths faster than any human attacker. Here's the maturity assessment and 90-day roadmap every CISO needs before Q4 agent deployments.

June 30, 2026 · 15 min read
Agentjacking

Agentjacking: AI Agents Hijacked via Fake Bug Reports

Security researchers demonstrated a new attack class called Agentjacking that hijacks AI coding agents through fake Sentry error reports — no credentials stolen, no servers breached, no malware deployed. A single POST request with embedded markdown turned a Fortune 100 company's AI coding agent into an exfiltration tool. Tenet Security found 2,388 organizations exposed and achieved an 85% success rate across Claude Code, Cursor, and Codex. The NSA had already warned about this exact vulnerability class. Enterprise attack surface assessment and security hardening checklist inside.

June 28, 2026 · 19 min read
OPAQUE

77% Wrote AI Agent Policies. Only 26% Can Enforce Them.

OPAQUE 3.0 launches with Agent Manifest and Confidential MCP — the first verifiably governed Model Context Protocol implementation — bringing cryptographically provable trust to enterprise AI agents. Built on Microsoft's open-source Agent Governance Toolkit, the platform closes the 51-point gap between writing AI security policies and enforcing them with hardware-signed proof.

June 25, 2026 · 16 min read
AI agent security Articles | THE D*AI*LY BRIEF