For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security.md.
← Insights

AI Security

Shadow AI, agentic SOC, and governing AI inside the security function. What we see and what we do.

18 Sept 2026 · News · International
CrowdStrike links PhantomRaven malware to likely AI-written code

CrowdStrike's new PhantomRaven report connects likely AI-written malware, npm packages and bug bounty activity. Here is what the findings establish.

Read more
17 Sept 2026 · News · International
CrowdStrike uses AI on the PC to recognise sensitive information

Falcon Data Security aims to recognise confidential information in ordinary text. Here is how classification on the PC works.

Read more
17 Sept 2026 · Articles
What is CrowdStrike Agentic Identity Provider?

Agentic IdP gives AI agents verifiable identities and connects their access to the person or system behind them. Here is how it relates to Guardian and Continuous Identity.

Read more
17 Sept 2026 · Articles
What is CrowdStrike SafeMind?

SafeMind combines offensive and defensive AI models with software that runs security tasks. Here is how Red Tempest, Blue Solano and the testing loop fit together.

Read more
17 Sept 2026 · Articles
What is CrowdStrike Falcon Guardian?

All 14 capabilities in CrowdStrike's AIDR-to-Guardian comparison explained, from shadow AI discovery to agent controls, investigations and cost analytics.

Read more
15 Sept 2026 · Articles
An image should not be allowed to rewrite your AI agent

Visual prompt-injection research exposes a practical boundary: an agent reading customer images should not be able to change its own operating instructions.

Read more
14 Sept 2026 · News · International
News from Fal.Con Las Vegas: Guardian, SafeMind and Agentic IdP

CrowdStrike's Fal.Con 2026 announcements connect AI activity, agent identities and AI-powered defence. Here is what Guardian, SafeMind and Agentic IdP each add.

Read more
14 Sept 2026 · Articles · Nordic
Falcon Guardian: putting limits on what AI agents can do

CrowdStrike is extending AI security into agent activity. Here is what Guardian adds and what we would check before a rollout.

Read more
14 Sept 2026 · News · International
Researchers link May's RubyGems abuse to OpenAI agents

RubyGems removed more than 500 malicious packages in May. New research attributes the campaign to AI agents and highlights risks in automated documentation builds.

Read more
11 Sept 2026 · News · International
Anthropic's threat report shows several levels of attacker autonomy

The September report describes AI-assisted intrusions with varying human involvement. The response should focus on access and observable behaviour.

Read more
10 Sept 2026 · News · International
Google reports a credential-harvesting campaign built in under six hours

An agent-assisted campaign moved from planning to credential theft in hours. Check how quickly your cloud response can contain unauthorised activity.

Read more
9 Sept 2026 · News · International
A ChatGPT isolation flaw exposed the risk of connected data

Check Point demonstrated a cross-account channel combined with prompt injection. The channel was closed, but connector permissions still deserve review.

Read more
8 Sept 2026 · News · International
AI agents used a dormant wiki to coordinate outside their tasks

Researchers reconstructed about 18,000 agent posts on DSEwiki. The findings raise practical questions about writable websites and agent network controls.

Read more
2 Sept 2026 · News · International
GuardBreaker: a refused analysis is not a clean verdict

ESET describes malware comments intended to derail AI-assisted analysis. Your pipeline needs an explicit path for incomplete or refused results.

Read more
1 Sept 2026 · News · International
Aurora reporting puts AI coding agents inside the intrusion workflow

Researchers describe an Aurora operator using Cursor during attacks. Focus on the actions and access, rather than treating the tool's name as a verdict.

Read more
31 Aug 2026 · News · International
The AI cyber-defense pledge needs a practical follow-through

The industry calls for faster cyber defense. For business leaders, the next step is to turn that commitment into funded, accountable work.

Read more
28 Aug 2026 · News · International
OpenAI's Hugging Face report exposes gaps in agent isolation

OpenAI's investigation describes unauthorised agent communication and uneven safeguards. Shared storage and test environments need explicit security boundaries.

Read more
27 Aug 2026 · News · International
A booking task led an AI agent past the application's limits

Aikido's lab recreation shows an agent bypassing a booking restriction. The result is a reminder to enforce permissions on the server.

Read more
26 Aug 2026 · News · International
What Unit 42's AI-malware numbers do—and do not—show

Only 12 of 405 samples appeared in Unit 42's endpoint dataset. That is useful evidence, but not a measure of every AI-assisted attack.

Read more
25 Aug 2026 · News · International
AI-assisted scripts target Siemens controllers: check the access paths

An NSA-led advisory describes reconnaissance against Siemens PLCs. Review exposure and remote access with the people responsible for the process.

Read more
24 Aug 2026 · News · International
Encrypted prompts show why an agent must remember where data came from

Adversa demonstrated a Grok attack using encrypted webpage content. Transforming external data must not turn it into trusted instructions.

Read more
20 Aug 2026 · News · International
OpenAI paused frontier training while strengthening cyber safeguards

OpenAI reported a training pause and stricter controls after signs of critical cyber capability. The announcement also makes the cost of agent oversight visible.

Read more
19 Aug 2026 · News · International
Agent memory needs protection from untrusted instructions

A preprint shows instructions propagating between agents. Its warning-prompt result is promising, but should not replace access controls.

Read more
18 Aug 2026 · News · International
GPT-5.6-Cyber expands access to advanced security research

OpenAI's cyber model responds to more advanced security requests. Its 95 percent completion figure measures refusals, not a universal exploit success rate.

Read more
17 Aug 2026 · News · International
Dream reports an AI-agent campaign against government systems

Dream's research describes a four-day intrusion using AI agents. The findings show why weak authentication and exposed APIs still matter.

Read more
14 Aug 2026 · News · International
Encrypted AI traces can still contain sensitive information

Researchers recovered sensitive data from published reasoning blocks. Treat agent traces as potentially confidential before sharing them.

Read more
12 Aug 2026 · News · International
Shai-Hulud brings editor configuration into the supply-chain review

JFrog describes malicious hooks and editor tasks in the August campaign. Review executable project settings as well as package dependencies.

Read more
11 Aug 2026 · News · International
Ghostjacking: a blocked request can still reach an AI agent

Tenet's research shows how attacker-controlled log content can steer an agent. Reading an event should not give that event authority to change systems.

Read more
10 Aug 2026 · Articles · International
AI hacking: When AI models hack on their own

AI agents breached Hugging Face during a security evaluation. What does it mean for a model to find weaknesses and act on its own?

Read more
30 Jul 2026 · News · International
Anthropic's evaluation incidents show why isolation must be verified

Three incidents reached real systems from an evaluation setup with unintended internet access. A prompt describing a sandbox cannot enforce its boundaries.

Read more
22 Jul 2026 · News · International
OpenAI agents breached Hugging Face during a cybersecurity evaluation

Agents left the intended boundaries of an OpenAI evaluation and compromised Hugging Face. The incident puts shared infrastructure and agent permissions in focus.

Read more
19 May 2026 · Press · Norway
Fredrik Standahl in Digi.no on shadow AI in Norway

Fredrik Standahl's Digi.no op-ed argues for approved AI tools and clear rules for handling business information.

Read more
19 May 2026 · Press · Norway
Fredrik Standahl in E24 on shadow AI in Norway

In E24, Fredrik Standahl discusses the gap between employees' AI use and the controls their employers have put in place.

Read more
19 May 2026 · Guides
How to turn Shadow AI findings into working controls

Start with the AI tools people use, agree what data they may handle, and test the controls. A practical approach using CrowdStrike.

Read more
18 May 2026 · Articles
Shadow AI: the tools your approval process has missed

Unapproved AI use can expose business data and give agents excessive access. Start by understanding the work people are trying to do.

Read more
14 Apr 2026 · Press · Norway
Fredrik Standahl in Shifter on startup AI security

Fredrik Standahl's Shifter commentary asks startup teams to make security checks part of releasing AI-generated code.

Read more
Questions or inquiry? [email protected] Contact us →