Interviews | July 16, 2026

AI Agents Have Become Force Multipliers for Attackers


Cisco | KnowBe4 | Primary | Vega

Amy Chang
Head of AI Security Threat Researcher, Cisco

Cisco

Q1. What are the main takeaways for enterprise organizations from Cisco's State of AI Security Report 2026?

2025 was the end of the AI-assisted era; 2026 has unleashed the AI-driven era with a vast proliferation of capabilities, dependencies, and resources dedicated to AI applications and AI agents. As those AI assets multiply, the attack surface expands with them. The risk sharpens wherever an AI system combines broad capability with privileged access and a path to act or exfiltrate data: In those conditions, an AI that is compromised by an attacker—or simply misaligned—can cause damage at a speed and scale with no traditional equivalent.

The starkest example is a state-sponsored campaign in which a threat actor subverted an agentic tool and used it to automate the majority of a multi-target espionage operation. Criminal groups follow the same logic, using AI to automate and simplify their operations. Agents have become force multipliers for attackers, not a future risk.

Underneath this is a readiness gap: In 2025, most organizations Cisco surveyed planned to put agentic capabilities into core business functions, but only about a quarter felt ready to do so securely. If an organization's risk surface is now the entire AI lifecycle—from data to models to supply chain to deployed agents—there's a lot of new ground to cover and protect.

Much of that ground is the connective tissue of the AI economy: the Model Context Protocol servers, agentic and multi-agent frameworks, and tens of thousands of dependencies and resources that proliferated to facilitate agentic workflows (e.g., SKILL.md files). These tools were adopted far faster than they were secured, setting the stage for potential cascading security failures. Agents may be powered by unsafe models, connected to compromised resources, or granted excessive agency (meaning they hold more access than they should), each of which requires a different approach to secure.

Addressing this starts with defense-in-depth: choosing resilient models, layering protections that detect anomalous behavior, prioritizing threat-specific mitigations, and evaluating continuously rather than once at launch.

Q2. What security assumptions are enterprises making about AI agents today that you think they'll look back on as mistakes? What should they be doing instead?

First, and most damaging: It's a mistake to assume that the model is your security boundary and that its guardrails can be trusted to prevent misuse or harmful outputs. A model cannot reliably separate instructions from its operator from content it ingests; to a model, it's all tokens in one window. Our own testing makes this concrete: We've assessed over 100 open-weight and proprietary models on our LLM Security Leaderboard against our adversarial testing, successfully bypassing model guardrails in both single prompt and in longer (multi-turn) conversations, achieving jailbreaks attack success rates as high as 93 percent. Given that human interactions with AI rarely stop after a single back-and-forth, we need to adversarially test models in realistic scenarios such as agentic workflows or longer context conversations. And because these systems are nondeterministic (meaning the same input can produce different outputs), a model that passes your test today can fail it tomorrow. Point-in-time testing should be replaced with continuous, automated evaluation of entire agentic workflows.

The second faulty assumption: that the AI supply chain can be trusted. Enterprises may need to relearn hard lessons from traditional security, where supply chain risks have been behind some of the biggest breaches in history. Most AI model repositories offer no cryptographic assurance of who trained a model, on what data, or whether it has changed since publication. As automated pipelines quantize, merge, and fine-tune models, backdoors can persist while benchmark scores stay clean. If organizations are not aware of who did what to a model, it will complicate incident response and remediation measures if something goes awry. Organizations can also unknowingly deploy models fine-tuned in jurisdictions subject to export controls or data-sovereignty rules, which create compliance risk. Treat model artifacts with the chain-of-custody rigor you'd apply to signed binaries from download through fine-tuning to deployment.

Third: that identity and access management built for humans covers agents. It doesn't. Agents authenticating and collaborating with other agents expands the identity surface well beyond people and service accounts. Attackers exploit the implicit trust among agents, using methods such as impersonation, session smuggling, capability escalation, to move laterally with no human involved.

Assume compromise and contain it. Leverage Cisco's Integrated AI Security and Safety Framework to identify every application or agent with the lethal combination of untrusted input, sensitive access, and external reach. Remediate those first by extending zero trust to agents and enforcing runtime policy independent of the model, so a hijacked agent cannot exfiltrate anything. Encouragingly, the newest agent platforms Cisco is shipping this year build that containment in.

Q3. What themes and technologies is Cisco planning to highlight at Black Hat USA 2026? What conversations or demonstrations do you hope will resonate most with customers and the broader security community?

Cisco's center of gravity is focused on defending at AI speed. That calls for securing agentic AI across its full lifecycle. A year ago, we were still asking whether a given model was safe. While that remains an important question, we must now also consider: if this agent is compromised, what can it reach, and how fast can we know? We can't keep up with AI-enabled adversaries if we can't trust our own AI agents and systems.

We are providing solutions to contain AI risk: The goal of AI red teaming is to find and explain high-impact, customer-specific AI vulnerabilities in production workflows, not just model outputs. Cisco AI Defense has developed an AI red teaming approach that supports customer-define objectives, and autonomously plans, executes, and judges attacks across the full agentic workflow, returning evidence-backed findings and deep contextual insights.

We are excited to showcase how Splunk detects and responds to threats at machine speed, reducing an attacker's freedom to operate through faster correlation and response. Bolstering that capability, my AI Threat Intelligence & Security Research Team, along with Cisco Talos, are shifting uncertainty back onto the attacker. We combine frontline threat research and attacker knowledge to expose how adversaries adapt in an AI-accelerated landscape, with that intelligence integrated across the Cisco portfolio.

Cisco is focused on helping defenders gain the advantage in an era where autonomous agents, frontier models, and AI-enabled adversaries are reshaping the speed and scale of AI compromise and cyber risk. While the possibilities for compromise and attack are endless, you don't have to boil the ocean. Start with the Integrated AI Security and Safety Framework to understand what risks exist in your organization. Inventory your models and agents, and home in on the ones with untrusted input, sensitive access, and external reach. Contain those first. Treat agents like any privileged, internet-facing system: Apply defense-in-depth and zero-trust principles.


Jack Chapman
SVP Threat Intelligence

KnowBe4

Q1. How do traditional employee training and awareness programs need to evolve to address AI-enabled phishing and social engineering attacks? How should organizations rethink their strategies now that phishing is targeting entire workflows rather than just the email inbox?

Traditional security awareness training was built for a different threat landscape, one where phishing had obvious tells: misspelled domains, clunky grammar, implausible pretexts. That's gone. Today the majority of phishing emails are AI-assisted. The grammar is perfect. The context is researched. Yet too much training is still one-size-fits-all, despite attackers being more sophisticated and targeted than ever before.

The shift organizations need to make is from awareness to behavior. Knowing phishing exists doesn't protect you. What protects you is building the instinct to pause, verify, and question under pressure and making that instinct automatic through continuous, realistic practice that reflects what real attacks look like right now, not last year’s compliance module.

Another key consideration is that agents are now entering the workforce, it’s not just about protecting people, but our AI Agents as well, who are just as vulnerable to social engineering/prompt engineering and other attack vectors.

Organizations need to treat workforce risk as a system-level problem. That means understanding which users are highest risk, in which contexts, and delivering targeted intervention at the moments it matters most, not in a session six months ago. The case for personalizing training based on individual risk profile is clear: a generic programme where each user’s risk is not considered will always underperform against a targeted attack.

The good news is that people are not the weak link they've been labelled. When they have the right context at the right moment, they make good decisions. The goal is engineering that context into their daily workflow, empowering people to be genuine cyber advocates, not just compliance checkboxes. Combining advanced technology with an engaged, risk-aware workforce leads to far better outcomes than either can achieve alone.

Q2. Is human detection still a viable layer of defense against phishing and social engineering attacks? If not, what should organizations be doing differently to protect employees from AI-driven phishing and social engineering attacks?

The question assumes a binary that doesn't hold up in practice. Human detection hasn't become useless; it's become insufficient on its own. That's a meaningful distinction. This focuses our security layers on the traditional three approaches: Technology, Humans and Policy. All of which are just as important today as every before, however a focus on where these pillars overlap is crucial. If any pillar operates independently of the others, it can lead to friction and opportunities for attackers.

A well-trained employee who pauses before wiring money to an unfamiliar account, or questions why their CEO is asking for gift cards over text, is still preventing real damage. That instinct has value. The problem is we're asking people to make increasingly difficult judgement calls against attacks that have been engineered specifically to defeat human intuition; at volume, at speed, under pressure.

What organizations should be doing differently is building defense in depth and in harmony where technology and people operate as a system, not a fallback chain. That means deploying email security that catches what legacy tools miss; using proactive detection methods that catch the zero days and BEC attacks that are successfully getting through legacy tools. But why stop there? They should use that as training opportunities for the work force to ensure the most relevant real time training that is possible.

It means giving users real-time, contextual signals the moment a suspicious email lands, reinforcing their existing training. And it also means measuring human risk continuously, so you know where your exposure actually is.

The workforce layer remains essential particularly for the attacks that get through everything else. But it performs best when it's supported by technology that reduces the cognitive load, not one that offloads the entire problem onto the individual. Security in depth is still the best practise. Combining advanced tooling with an empowered work force is the best way to keep secure and frustrate the attackers.

Q3. KnowBe4 has often used Black Hat to introduce new capabilities and share research on how the human risk landscape is evolving. What can attendees expect from KnowBe4 at Black Hat USA 2026? Are there any new technologies, research, or product announcements you'll be highlighting?

We have a lot of new innovations across our products and research! We will be show casing new updates across our entire product set, however the one to really call out is our new Agent Risk Manager product. It is the step forward to protect organizations use of AI as well as AI Agents. It sits between users and AI agents (Copilot, Claude, Gemini, ChatGPT etc.) to detect threats, prevent data leakage, and coach users in real time when they do something risky.

This is a key and timely innovation when looking at how we work is changing and how the threat landscape is rapidly evolving to attacks both humans and agents. It also It naturally continues Knowbe4’s Journey and evolution from training and protecting employees - to securing the entire workforce - Humans and AI Agents.


Michael Marx
President

Primary

Q1. What are the biggest challenges your customers face in gaining end-to-end visibility and control over data flows across the network stack? Where do traditional approaches to monitoring and controlling data movement break down in today's hybrid and cloud-native environments?

I think we've reached an inflection point where the industry needs to acknowledge that visibility, by itself, is no longer the problem we're trying to solve. Most enterprises have invested heavily in tools that generate extraordinary amounts of telemetry. They can observe networks, endpoints, identities, cloud infrastructure, applications, and data stores independently. Yet when a board member asks a simple question like, "Can we confidently explain how this piece of sensitive data moved through our environment, who touched it, and whether every interaction should have occurred?" the answer is often surprisingly difficult.

The reason is that modern enterprises no longer operate as bounded networks. They operate as dynamic ecosystems of identities, services, workloads, APIs, AI models, and third-party platforms that continuously exchange information across environments. Traditional monitoring architectures were built to observe infrastructure. Today's challenge is understanding trust relationships that exist above the infrastructure.

What organizations increasingly need is not another monitoring platform, but a unified control plane capable of establishing continuous trust across every interaction. End-to-end visibility only becomes meaningful when it is paired with context: cryptographic identity, policy, provenance, and governance that persist regardless of where the workload resides or how the data moves. The conversation is shifting from asking, "Can I see what's happening?" to "Can I continuously verify that every interaction is legitimate?" I believe that distinction will define the next generation of enterprise security.

Q2. With AI agents and autonomous workflows generating significantly more machine-to-machine traffic, what new security or operational challenges do you expect organizations to face in the short term?

The industry is preparing for an explosion in machine-to-machine communication, but I think the more significant shift is that we're moving from programmable automation to autonomous decision-making. AI agents are no longer passive software executing predefined logic. They are beginning to discover resources, invoke services, coordinate with other agents, and initiate actions independently, often at machine speed and at massive scale. That fundamentally changes the security model.

For decades, enterprise security has centered on authenticating people and protecting devices. In the near future, organizations will manage orders of magnitude more non-human identities than human ones, each capable of initiating privileged actions across increasingly distributed environments. The operational challenge won't simply be managing volume. It will be establishing confidence in autonomous behavior.

The organizations that adapt most successfully will shift their focus away from securing individual systems and toward governing relationships. Every interaction, whether initiated by a person, workload, service, or AI agent, should be continuously verified against identity, intent, authorization, and policy before trust is extended. Trust must become dynamic rather than assumed.

I believe AI will expose a reality that has been building for years: security cannot continue to be built around the perimeter or even around the user. It must be built around trusted interactions. Organizations that establish a unified control plane capable of continuously verifying those interactions will be positioned to embrace AI confidently, while those relying on fragmented security models will find governance becoming increasingly difficult to sustain.

Q3. What announcements, new product capabilities, research demos or other events has Primary lined up for Black Hat USA 2026? What is your main messaging at the event?

Primary is here. The Unified Zero Trust Control Plane. Control What's Next.


Eli Rozen
Co-Founder and CTO

Vega

Q1. How do security architectures need to evolve to keep pace with the accelerating speed at which attackers are exploiting newly disclosed vulnerabilities? Where are organizations still most constrained today—technology, process or the operating model?

Attackers now weaponize new disclosures with frontier AI, and defenders inherited an architecture that was never built for it. The legacy SIEM was designed for centralized indexing and log compliance in a different era: filter data before you store it, freeze it into rigid schemas, pay again every time you want to see more. So, teams drop or cold-store the telemetry they can't afford to ingest, and the data an attacker reaches first is often the data you can't see. Bolt AI onto that and you get a faster interface on the same broken foundation. An AI summary of incomplete data is still a decision made on incomplete data, delivered with more confidence.

Architectures have to evolve so that security analytics reach any data, anywhere, immediately, with no ingestion tax and no migration prerequisite. That means querying every source where it lives, from the SIEM to the data lake to cloud logs and normalizing it as you go instead of months later behind a parser backlog. If you're compromising today on which data you can afford to ingest or which systems you can actually see, those gaps just became critical exposures. Cost and complexity used to justify leaving data dark. Now that gap is the exposure.

Where are teams most constrained? Not the technology, and not the engineers. It's the operating model. For twenty years the job was defined by a queue: write a rule, wait for it to fire, triage what fires, repeat. Adversary breakout is measured in minutes now, and a queue is worked in hours, so that model can't scale against AI-paced attacks, no matter how many people you add. The teams pulling ahead are changing the model itself, directing AI across detection, investigation, response, and tuning instead of clearing alerts one at a time.

Q2. For a SOC accustomed to a single consolidated SIEM view, what does adopting a federated approach to analyzing and investigating threats require upfront? What tradeoffs do organizations accept by not centralizing their data?

The premise hides an assumption worth challenging that a consolidated SIEM ever gave you a single view of everything. It didn't. It gave you a single view of the fraction you could afford to ingest. The rest sat in data lakes, cloud logs, and cold storage, out of reach. The single pane was always partial.

Federation flips that. Instead of hauling your data into one index, you send the query to the data, wherever it already lives. Done right, it's fast, not the slow fan-out people picture: the index sits in place beside each source, normalization happens as the query runs, and results return in seconds. What it requires upfront is less than teams expect and different from what they fear. You don't rip and replace, and you don't run a migration. You do three things: normalize data to a common schema as it's queried, so results come back consistent with no parser backlog; expose one interface that people and AI agents share, so there's no separate, thinner AI path into your estate; and insist that every query, and every piece of evidence behind a verdict, is deterministic and auditable. Without that last part, a federated hunt is just a faster way to be confidently wrong.

The honest tradeoff isn't lost visibility. It's a shift in discipline. You trade the comfortable fiction of one central index for the work of governing access and normalization across many sources. In return, you stop paying to see your own data, and you close the blind spots that centralization created.

The tradeoff of staying centralized is the one that should worry you: you keep accepting gaps because the data was too expensive to ingest. Against AI-paced attackers, the data you left out is often the data they reach first.

Q3. What does Vega plan to highlight at Black Hat USA 2026? What do you want attendees to take away from your company's participation at the event?

Two things, and they're connected.

The first is the foundation: the post-SIEM era. AI changed how fast attackers move, and the legacy SIEM is now the slowest tool in the SOC. Our whole presence, right down to the booth, is built around one idea: your security analytics should reach any data, anywhere, immediately, with no ingestion, no migration, and no blind spots. We'll show what that looks like in production. One query across every source, autonomous triage and investigation against the full estate, all through a single interface that people and AI agents share.

The second is the part I'm most excited about, and it's the piece the industry keeps missing. A detection has only ever carried one piece of its own lifecycle: the trigger. Sigma standardized how we write that match, and it was a real step forward, but the match was never the hard part. The judgment that follows is the hard part: deciding whether it's real, investigating what it means in your environment, and tuning the rule so it fires sharper next time. That expertise lives in playbooks nobody reads and in the heads of your best engineers, and it walks out the door when they leave.

So, we asked a different question: what if all of that traveled with the detection itself? The triage logic, the investigation steps, the organization-specific context and workflow that make a verdict defensible, carried by the detection instead of the person who wrote it. That's the shift we're building, and Black Hat is where you'll see it live. Come find us at booth 3452, or catch my session on the Pulse Stage, Thursday, August 6, at 2:40 PM.