AI Summary
Get a short AI-generated description of this article
Last week's threat intelligence had a familiar shape: known vulnerabilities exploited faster than teams could patch them, a mass campaign built on nothing more exotic than a default admin account, and analysts warning again that AI is now doing the attacking as much as the defending. Here's Vigilnz's take on what actually matters for teams securing AI agents, tools, and applications.
A logistics company's internal ops agent had standing access to a device management console the kind of console that ships with a generic admin login nobody got around to rotating. Nobody had to phish a credential or write an exploit. An attacker found the same door 86,000 other Fortinet devices left open, walked through it using the vendor default, and from there quietly rode the agent's existing session straight into the systems it was trusted to manage. The agent didn't get hacked. It just never had an identity distinct enough to notice the difference between its owner and an intruder.
The pattern behind the noise
Strip away the CVE numbers and the headline campaign names, and last week's briefings kept circling back to three things:
- Known vulnerabilities are still the fastest path in. Two fresh entries landed on CISA's Known Exploited Vulnerabilities catalog last week alone a PLM platform flaw and an SSRF bug in enterprise call-management software both already under active attack before most security teams had finished triaging the advisory.
- Default credentials still work at scale. A state-linked campaign compromised tens of thousands of network devices using nothing more sophisticated than accounts that were never changed from their factory settings. It's not a new technique. It's just still effective, because inventory and identity hygiene remain the two things most environments get wrong.
- AI is now explicitly named as an attack accelerant. Personalized phishing at scale, automated exploit chaining, prompt injection, model poisoning these aren't hypothetical categories in a slide deck anymore. They're showing up in near-term threat forecasts as things security leaders need to plan against this quarter, not this decade.
None of that is surprising on its own. What's worth sitting with is where these three trends intersect: agentic AI systems inherit every one of these weaknesses and add a new one on top. An AI agent calling a tool or a downstream service is, functionally, a non-human identity with standing access often broader access than the human it was built to assist. If that identity is never inventoried, never scoped, and never distinguished from "just another authenticated session," it becomes the exact kind of door a default-credential campaign or a KEV exploit walks straight through.
Why "asset inventory" now has to include agents
Traditional advice after a week like this is straightforward: inventory your internet-facing assets, audit for default and shared credentials, and scan for KEV-listed vulnerabilities in your dependency tree. That advice is still correct. It's just incomplete.
Most organizations can tell you how many servers, containers, and third-party libraries they're running. Very few can tell you how many AI agents currently hold live credentials, which tools those agents are authorized to call, or what happens if one of those tool calls gets hijacked mid-session. The agent economy has quietly recreated the non-human identity sprawl problem that took the industry a decade to get a handle on for service accounts and API keys except this time the identities can be manipulated through natural language, not just stolen.
That's the gap vigilnz Agentsec pillar exists to close. AI Security Gateway sits in front of agent traffic to enforce policy on what an agent is allowed to call and with what data, so a compromised session can't silently escalate the way it did in the Fortinet campaign.
Agent Guard gives every agent its own scoped, monitored identity instead of inheriting a human's blanket permissions the difference between an intruder finding one open door and finding a locked one at every hop. Tool Guard extends that same discipline to the MCP servers and third-party tools agents increasingly call on your behalf, which is where a lot of this year's supply-chain and prompt-injection risk actually lives.
What to check this week
You don't need a six-month roadmap to make progress. Three things worth doing before Friday:
- List every AI agent with production access internal ops bots, customer support agents, coding assistants with repo write access and confirm each one has its own credential, not a shared or inherited one.
- Match your model and tool inventory against known-vulnerable components the same way you'd run a KEV scan against your dependency tree. AIBOM makes this a query instead of a fire drill.
- Red-team at least one production agent for prompt injection and tool-call abuse before an attacker does it for you. Most teams have never actually tried to break their own agent AI Red Teaming service does exactly that.
Ransomware volumes, state-actor campaigns, and default-credential sweeps aren't going away, and neither is the pressure on security teams to show measurable risk reduction to the board. The organizations that stay ahead of this cycle are the ones treating AI agents as first-class identities to govern not conveniences to bolt on after the fact.
Curious what's actually reachable through your own agents and tools right now? That's a conversation worth having with vigilnz before it shows up in someone else's threat briefing.
