SANS Urges IT Security Teams to Close Open Doors to AI Agents – datensicherheit.de
Aktuelles, Branche– geschrieben von cp am Sonntag, August 9, 2026 14:28 – noch keine Kommentare
SANS Urges IT Security Teams to Close Open Doors to AI Agents
SANS Institute instructor Andy Smith warns that AI agents are increasingly escaping test environments and targeting other software systems. He says the key challenge is not security awareness, but the lack of practical testing against real-world AI-driven attacks.
[datensicherheit.de, 08/09/2026]Andy Smith, a “Certified Instructor” at the SANS Institute, comments on incidents involving AI agents in his latest statement: “So now Meta has joined the list this week. Reports are piling up of AI providers whose AI agents are breaking out of test environments and hacking other software providers.” To prevent this, Smith says, all companies need to internalize the basics of defending against attacks. These and other incidents that have come to light are causing concern among IT security teams around the globe. That’s because the vulnerabilities exposed by such incidents have nothing to do with“awareness.” Smith emphasizes: “The experts already know that AI-driven attacks are taking place. They’ve read the headlines.” The gap lies in the fact that most teams have never tested their own environments against the actual behavior of these attacks—and this behavior refutes many of the assumptions on which detection programs are based.
Andy Smith describes AI agents used by attackers as tremendous “performance multipliers”
AI Agent Testing Without Strong Controls Poses Serious Security Risks
Smith explains: “Both perspectives have merit. We are undoubtedly seeing progress in AI’s ability to find and exploit security vulnerabilities. We also see the potential to deploy a large number of agents for an offensive operation. This is an enormous performance multiplier for attackers.”
Ultimately, however, artificial intelligence (AI) must still go through the same steps that a human would have to perform. “We’ve known for years that it’s often forgotten or misconfigured resources that give attackers their initial foothold in a company, and that remains true even in the age of AI.”
Furthermore, recent reports have shown that the same applies to AI agents that escape from supposedly isolated “sandbox” environments. It is a sign of great negligence “that companies conducting such tests fail to implement sufficiently robust control mechanisms, which has led to attacks on other parties.”
Reported Cases of Runaway AI Agents Raise Questions
A look at some of the reported cases in which AI agents escaped from test environments and were able to compromise other IT environmentseams should ask themselves
Rules for assessing the severity of alerts are based on the assumption of an active attacker or a critical event. However, an autonomous AI agent may not represent either of these scenarios.
According to Smith, preparing for such incidents means having what is known as “severity logic” in place—logic designed to detect slow-moving activities across multiple paths where no single event appears critical, while still ensuring that the person on duty is notified even outside of regular working hours.
Deception as the Key to Detecting Automated Attacks
Automation serves as a cover: “If security teams have no idea how their legitimate automation normally behaves, malicious automation can blend in seamlessly” warns Smith. But if the behavior of one’s own systems is understood well enough that the behavior of an intruder stands out immediately, much has been gained.
Deception works better on AI agents than on humans. A cautious human attacker might overlook a “canary token.” “An agent issuing thousands of commands could trigger one within the first hour.”
One affected security team openly admitted that it should have employed deception measures. In most environments, these are still lacking. When it comes to defending against automated attackers, this means forgoing one of the most cost-effective detection methods with the highest signal-to-noise ratio.
AI agents are here to stay—emergency plans must be adjusted accordingly
There is a fourth question regarding readiness assessments that almost no one has asked so far: “If a self-hosted ‘OpenWeight’ model is part of the incident response contingency plan, have security teams already checked it for hidden behavior?”
This model is now part of the security infrastructure and deserves the same thorough scrutiny as everything else they must rely on during a security incident.
Smith’s conclusion: “This exercise serves as a diagnostic tool. If the answers turn out as they will for most teams, security teams now have a concrete, prioritized list of improvement measures based on a real incident—and no longer just on a hypothetical scenario.”
Key findings:
- AI agents can be used as useful tools or as dangerous weapons—since they are here to stay, all IT security managers should be aware of this dual nature and take appropriate action accordingly.
- Testing AI agents without being able to securely contain and control them is irresponsible.
- Thefundamental problems of IT and computer science are by no means new—but AI agents bring vulnerabilities to light more quickly and consistently than humans ever could.
- The pressure on companies and institutions to act is mounting—on the one hand, regulations are increasingly focusing on decision-makers’ responsibility; on the other, potentially erratic AI agents are forcing the adoption of holistic IT security approaches.
- In the course of the digital transformation—that is, the extensive digitization and networking of nearly all areas of life—the boundary between the virtual and physical worlds is becoming increasingly blurred: politics and society, as well as companies and organizations, must face the challenge that AI agents, for example, can exert direct or indirect harmful influence on physical objects from cyberspace.
More information on this topic:
SANS
<a href="https://www.sans.org/about” rel=”nofollow noopener” target=”_blank”>About SANS Institute: Launched in 1989 as a cooperative for information security thought leadership, SANS (SysAdmin, Audit, Network, Security) Institute is the largest and most trusted provider of cybersecurity training, certifications, programs, and resources in the world. Our ongoing mission is to empower current and future cybersecurity practitioners with practical skills and knowledge that make the digital world safer, and to support the global cybersecurity community at every stage of their journey.
SANS
Andy Smith – Certified InstructorHead of Security Architecture at Sage
tagesschau, 06.08.2026
Nach Anthropic und OpenAI Auch KI von Meta dringt in fremdes System ein
DER SPIEGEL, 06.08.2026
Autonomer Angriff Auch KI von Meta hackte sich in eine andere Firma / Immer häufiger steckt KI hinter Cyberattacken. Nun ist auch ein Programm des Facebook-Konzerns Meta damit aufgefallen. Der Fehler soll auf einen Testpartner zurückgehen.
datensicherheit.de, 07.08.2026
Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht / Laut Medienberichten hatte die KI „Claude“ bei einem Sicherheitstest unerwarteten Zugang zum öffentlichen Internet erlangt
datensicherheit.de, 03.08.2026
„Claude“-Ausbrüche mahnen: KI-Modelle durch „Zero Trust“ einhegen / Sobald ein autonomer KI-Agent eine kontrollierte Umgebung verlassen kann, nimmt er die Grenzen einer Organisation nicht auf die gleiche Art und Weise wahr wie Menschen
datensicherheit.de, 03.08.2026
KI-Systeme: Wer testet, haftet für die Folgen / KI-Unternehmen müssen nun die richtigen „Leitplanken“ installieren, damit ihre Produkte nicht zur Gefahr werden
Aktuelles, Experten, Studien– Aug. 7, 2026 0:18 – noch keine Kommentare
Anstieg der Hardware-Preise in Folge KI-getriebener Halbleiter-Nachfrage
weitere Beiträge in Experten
- Claude-Phishing-Vorfall durch Versagen grundlegender KI-Sicherheitsarchitektur ermöglicht
Freitag, August 7, 2026 0:03 – noch keine Kommentare - Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
Donnerstag, August 6, 2026 8:53 – noch keine Kommentare - Digitalisierung der Schiene: TÜV-Verband fordert Modernisierung sicherheitsrelevanter Verfahren
Donnerstag, August 6, 2026 0:37 – noch keine Kommentare - Deutschland im EU-Digitalranking auf Platz 17
Dienstag, August 4, 2026 0:47 – noch keine Kommentare - „Archetyp Market“: Nach Abschaltung der Darknet-Handelsplattform nun Anklage gegen mutmaßlichen Betreiber
Dienstag, August 4, 2026 0:12 – noch keine Kommentare
Aktuelles, Branche– Aug. 9, 2026 15:51 – noch keine Kommentare
6 Strategies for Maintaining Cyber Resilience During Peak Vacation Periods
weitere Beiträge in Branche
- SANS Urges IT Security Teams to Close Open Doors to AI Agents
Sonntag, August 9, 2026 14:28 – noch keine Kommentare - Offene Türen für KI-Agenten schließen – das SANS Institute gibt IT-Sicherheitsteams Empfehlungen
Sonntag, August 9, 2026 0:58 – noch keine Kommentare - 6 Ratschläge zur Sicherung der Resilienz auch in Zeiten erhöhter urlaubsbedingter Abwesenheit
Sonntag, August 9, 2026 0:37 – noch keine Kommentare - Existenzielle IT-Sicherheit treibt Deutschlands Krankenhäuser zur digitalen Aufrüstung
Samstag, August 8, 2026 0:54 – noch keine Kommentare - Zutrittskontrolle als Governance- und Cybersecurity-Priorität
Samstag, August 8, 2026 0:51 – noch keine Kommentare
Aktuelles, A, Experten, Service, Wichtige Adressen– Jan. 13, 2026 1:08 – noch keine Kommentare
Registrierung bei ELEFAND: Krisen- und Katastrophenvorsorge bei Auslandsaufenthalten
weitere Beiträge in Service
- DigiCert-Umfrage: Manuelle Zertifikatsprozesse führen zu Ausfällen, Compliance-Fehlern und hohen Verlusten im Unternehmen
Mittwoch, Juli 9, 2025 19:03 – noch keine Kommentare - Threat Hunting: Bedeutung und Wertschätzung steigt
Montag, Dezember 21, 2020 21:46 – noch keine Kommentare - Umfrage: 71 Prozent der IT-Entscheidungsträger besorgt über Mehrfachnutzung von Passwörtern
Dienstag, Juli 14, 2020 14:51 – noch keine Kommentare - Fast die Hälfte der Unternehmen ohne geeignete Sicherheitsrichtlinien für Remote-Arbeit
Montag, Juni 29, 2020 16:22 – noch keine Kommentare - Umfrage: Bedeutung der Konsolidierung von IT-Sicherheitslösungen
Freitag, Juni 12, 2020 15:30 – noch keine Kommentare
