AI · 74 giorni fa
Il punto non è più solo vedere come si usa l'AI, ma trattarla come un principal che può ereditare accessi, muoversi tra sistemi e restare attivo oltre la persona che l'ha creato. La difesa standard, pensata per utenti fissi e ruoli stabili, perde presa quando un agente accumula permessi, incrocia email, file, ticket e codice, e apre vie di abuso laterale difficili da attribuire.
Il 2026 SANS AI Survey segnala che il 78% delle organizzazioni usa già AI nella strategia di cybersecurity, ma il 63% riporta gravi carenze in detection e response e il 44% dice di essere ancora nella fase iniziale della policy. Le analisi di Unit 42 e la guidance di Microsoft convergono sullo stesso schema: gli agenti non sono solo strumenti, ma identità operative che possono conservare token, ampliare il proprio raggio d'azione e creare gap di auditabilità quando il lifecycle non è gestito.
Per i team che stanno distribuendo AI assistant o workflow agentici su SaaS, cloud e sistemi interni, il rischio reale è l'accesso non governato, non la qualità del modello. La questione diventa chiavi, deleghe e confini tra sistemi, non output sbagliati.
11 fonti che coprono questa storia
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report.
Agentic AI: Taming the Unpredictable
Agentic artificial intelligence is creating enough risks for organizations to demand a security reframe.
Least privilege for AI agents: Identity, access, and tool binding | Microsoft Security Blog
As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.
AI Can Find Bugs, But Human Knowledge Still Proves Them
AI speeds offensive testing, but unproven findings increase triage noise unless teams verify reachability, impact, and deployed context.
AI Agents Broke the Security Playbook. Here's What Replaces It.
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
SANS Warns of AI Governance Gap as Use by Security Teams Surges
SANS Institute says governance programs are still nascent even as AI failures and threats grow
AI used to help plan the break-in, now it's doing the break-in - Help Net Security
The Check Point 2026 Security Report reveals how AI is driving cyber attacks and enterprise security risks.
Sharp rise in AI adoption for cyber defense exposes major governance gap
A report by the SANS Institute indicates a split between senior security leaders and frontline practitioners.
The best defense against AI attacks turns out to be a skeptical human - Help Net Security
AI attacks now hit most organizations, and the 2026 SANS AI Survey finds the best defense is still a skeptical human analyst.
AI-powered breaches provide wake-up call for incident response
Recent incidents show attackers moving beyond LLM-written phishing lures to using AI across attack chains. Security teams must sharpen playbooks in response.
AI Security Report 2026 - Check Point Research
For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the […
Part of the PlainSec briefing for 2026-07-17