Discussion about this post

User's avatar
The AI Architect's avatar

Brillant writeup on something I totally missed too. The shift from treating agents as "apps" to treating them as identities with attack paths is exactly the kind of paradigm shift security teams need to internalize quickly. I had a similr experiance pulling apart a customer support agent last month and realizing it could basically read anything in SharePoint with no real audit trail. The idea of agents as tier0 assets alongside domain controllers is gonna take some convincing, but it's the right fram.

No posts

Ready for more?