Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agent attacks and silent exfiltration: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Straiker’s STAR Labs reports more than 1,700 successful adversarial scenarios across coding, productivity, and first-party agents, with 36% of successful coding-agent attacks reaching remote code execution and 91% of successful productivity-agent attacks ending in silent exfiltration. The findings show agentic security now depends on governing tool use, credentials, and context, not just scanning code or monitoring endpoints.

NHIMG editorial — based on content published by Straiker: Straiker Research Finds 36% of Successful AI Coding Agent Attacks End in Remote Code Execution

By the numbers:

Questions worth separating out

Q: What breaks when AI agents are given broad standing access?

A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check.

Q: Why do AI agents complicate existing IAM and PAM controls?

A: AI agents complicate IAM and PAM because they often inherit delegated credentials, operate across multiple systems, and keep acting after the initial approval moment has passed.

Q: How can security teams tell whether agent access is actually under control?

A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path.

Practitioner guidance

What's in the full report

Straiker’s full research covers the operational detail this post intentionally leaves for the source:

  • Per-agent attack findings across coding, productivity, and first-party deployments, useful if you need scenario-level evidence for internal risk reviews.
  • Research details on how malicious tools, prompt injection, and compromised contexts led to remote execution or silent exfiltration.
  • The report’s full breakdown of Model Context Protocol and tool-chain exposure, including the shared dependency patterns that expand blast radius.
  • The STAR Framework for AI Agent Security, which is the source’s structural model for mapping attack surface across layers and agent types.

👉 Read Straiker’s STAR Labs threat report on AI agent attack paths and blast radius →

AI agent attacks and silent exfiltration: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

AI agent identity is now a governance category, not a feature set. Once agents can read mail, browse the web, invoke tools, and touch credentials, they behave like non-human identities with delegated authority. That means the identity problem is no longer limited to human users or service accounts. It now spans agent lifecycle, privilege scope, and tool access, which is exactly where IAM and PAM programmes must extend their model.

A question worth separating out:

Q: Who is accountable when an AI agent takes an unsafe action?

A: Accountability should sit with the business owner of the agent, the team that provisioned the access, and the control owners responsible for monitoring and revocation. If no one can answer who approved the identity, the scope, and the oversight model, the governance framework is not complete enough for production.

👉 Read our full editorial: AI agent attacks are bypassing legacy controls and leaving no trace



   
ReplyQuote
Share: