FanDuel has restructured its security operations by replacing the traditional tiered analyst model with an all-engineer team focused on building and maintaining custom AI agents. These agents, such as SAGE, autonomously handle tasks like phishing detection, account takeover response, and incident response workflows, resulting in significant efficiency gains and a reduction in incomplete post-incident actions. The approach emphasizes starting with high-volume, specific use cases and gradually expanding automation, while also addressing new challenges like context rot in large language models.
Across the industry, the rapid adoption of artificial intelligence is driving a major shift in cloud security strategies. Traditional compliance-focused tools are being replaced by dynamic, behavior-based defense systems that leverage AI to monitor runtime context, such as live system calls and API requests, rather than relying on static configuration snapshots. This evolution enables defenders to detect subtle, real-time anomalies and better counter AI-powered attacks, as seen in increased investment and innovation in cloud and AI runtime visibility solutions.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.