Security leaders are warning that AI-accelerated software delivery and agentic AI are outpacing traditional application security and governance models, creating visibility and control gaps as code and infrastructure change faster than teams can inventory, review, and remediate. An OWASP Israel panel highlighted that AI agents can expand attack surface without clear ownership or asset inventory, making legacy “block the release on critical vulns” KPIs increasingly impractical and forcing CISOs to rethink how risk is prioritized and governed at high velocity.
Industry commentary and reporting echoed the same pressure on security leadership: CISOs are described as increasingly stretched thin, with calls to re-envision enterprise risk management to cope with accelerating change and expanding responsibilities. Broader AI-security discourse also points to emerging needs for identity and authorization frameworks for AI agents, and to the growing reality of AI systems finding large numbers of vulnerabilities in open-source components—raising the stakes for supply chain security, secure engineering enablement, and more disciplined operating models for security teams rather than relying on traditional gatekeeping alone.

Track how attackers are adapting to this technology.
15 events from the most recent confirmed update back to the earliest known activity.
A Dark Reading article warned that AI-generated automation in Microsoft 365 environments can be deployed while functioning correctly yet remain insecure, creating risks such as excessive permissions, silent data leakage, and compliance exposure. The piece highlighted Power Automate, Microsoft Graph scripts, SharePoint automations, Teams integrations, eDiscovery queries, and PowerShell scripts, and recommended code-style review, least privilege, workflow inventories, and monitoring before production use.
Help Net Security reported that Cobalt’s AI and Pentesting Pulse Report 2026 found AI and LLM-enabled systems generated high-risk security findings at 2.7 times the rate of other tested systems, with only a 38.4% remediation rate. The report also identified shadow AI as the leading cause of confirmed AI-related incidents, accounting for 44% of cases.
The Software Freedom Conservancy published recommendations addressing AI-assisted code submissions in open-source development. The guidance emphasizes contributor accountability, patch ownership, and reviewability rather than banning AI-generated code, amid concerns about insecure or unmaintainable changes entering software supply chains.
The UK National Cyber Security Centre published guidance describing a 'vibe coding spectrum' for AI-assisted software development, saying security risk depends on the code's purpose and the level of human oversight. The guidance recommends stricter review, testing, and verification for high-risk uses such as authentication, sensitive data processing, credential handling, and safety-critical systems.
Checkmarx research reported that 75% of organizations frequently or sometimes deploy software they know contains vulnerabilities, even as AI-driven time-to-exploit has dropped from hundreds of days to under two days. The report also highlighted more than 5,000 insecure AI-built 'vibe-coded' applications exposing sensitive corporate, personal, and medical data on the open web.
OWASP updated its GenAI Security Project guidance by separating recommendations for generative AI/LLMs and agentic AI systems, outlining 21 GenAI risks and introducing a first GenAI Data Security list covering 21 data-related issues. The update also expanded mapped security solution providers from about 50 to more than 170 and added reporting focused on AI-specific risks across DevOps and SecOps workflows.
The newsletter noted that Microsoft expanded its Secure Development Lifecycle to address AI-related development and deployment risks. This was cited as a defensive response to the growing security challenges posed by AI adoption.
The newsletter reported that OpenAI launched new ChatGPT Lockdown Mode and Elevated Risk labels as defensive measures. These were highlighted as part of broader efforts to improve security controls around AI systems.
The newsletter said NIST's NCCoE published a concept paper on applying identity standards to AI agents and opened it for public comment through April 2, 2026. The effort reflects growing work on identity and authorization frameworks for agentic AI.
The newsletter cited Sysdig research on a cloud intrusion that escalated from exposed S3 credentials to administrative privileges in under 10 minutes. The incident reportedly showed signs of LLM assistance and abuse of Amazon Bedrock for LLMjacking.
Google Threat Intelligence Group was reported to have observed actors linked to Russia, North Korea, China, and Iran using Gemini across stages of the attack lifecycle. The activity also included attempted model distillation through very large query volumes.
The newsletter reported that Anthropic's Claude Opus 4.6 identified more than 500 previously unknown high-severity vulnerabilities in open-source projects during testing. This was presented as evidence of rapid change in AI-enabled security research capabilities.
A Resilient Cyber newsletter described a real-world AI-in-the-loop CI/CD attack chain affecting the Cline AI coding assistant, involving prompt injection through GitHub issues and GitHub Actions cache poisoning that could enable secret theft. It also noted that Cline later confirmed an unauthorized npm publication had occurred.
An OWASP Israel panel discussed how AI-driven software development is outpacing traditional application security governance, inventory, and remediation processes. Panelists said AI agents are expanding attack surfaces faster than organizations can maintain visibility and enforce secure release controls.
A CSO Online news item reported that Google said an exploit was available for a newly identified Chrome zero-day vulnerability. The references do not provide technical details, affected versions, or patch information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
27 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcehelpnetsecurity.com
Open sourcelinuxsecurity.com
Open sourceitpro.com
Open sourceresilientcyber.io
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.