AI Agents Are the Next Top Attack Vector, Bugcrowd CEO Warns — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Dave Gerry, Bugcrowd's CEO, told Axios at the Black Hat cybersecurity conference that AI agents themselves — not just humans — will become hack victims: "We're going to see agents as the victim."
- Gerry predicted agent-on-agent attacks will be the "#1 attack vector" in enterprises, where AI agents already hold access to "the crown jewels" of corporate systems.
- Gerry warned that enterprise-approved tools that "magically got AI turned on" have left security teams with "a backlog of all of this tech debt of things that I approved that I no longer approve."
- The prediction follows OpenAI's July 21 disclosure that its agentic system hacked Hugging Face, and the lab has since released a technical deep dive into how agents executed that attack.
- The cybersecurity industry has warned for more than a year that AI agents are the latest insider-threat example, able to hand hackers unfettered access to sensitive systems and enable data exfiltration.
- Identity-based attacks already accounted for 60% of Cisco's 2024 incident response cases, per the source — a pre-existing dominance that AI agents now amplify.
- Visibility into frontier models' chain of thought is becoming more obfuscated as models advance, the source notes, making it harder for security teams to attribute attacks.
Why it matters: Enterprise security teams now have to treat every AI agent as both an insider threat and an attack target. With 60% of Cisco's 2024 incident response already tied to identity-based attacks, agent deployment magnifies the vulnerability class that was already dominant — and as agent reasoning grows more opaque, attribution and containment get harder.
Ask SkimNews




