Matt Hartman Warns Organizations to Treat AI Agents as Privileged Identities to Combat Expanding Cyber Attack Surfaces
Matt Hartman, former acting head of cyber for the US Cybersecurity and Infrastructure Security Agency, warns that AI agents are creating a new and growing attack surface for organizations. As AI moves from generating content to taking actions, agents are receiving access to sensitive systems and data, requiring defenders to treat every agent as a privileged identity. Hartman noted that AI-enabled social engineering attacks are increasing significantly, making traditional trust indicators less reliable. To counter these threats, experts suggest adopting agentic red teaming, where organizations use AI agents to attack their own systems. Evan Peña, co-founder of Armadin, highlighted that AI agents offer scale, expertise, and coverage that human-led assessments cannot match. Meanwhile, Rapid7's Christiaan Beek emphasized that traditional patch cycles are being overwhelmed by the volume of AI-assisted vulnerabilities. Beek argued that defenders must shift from focusing on severity scores to prioritizing exposure and reachability, as the gap between a patch existing and an exploit being weaponized has collapsed.
Sources
-
If you're not using AI to attack your own systems, your adversaries will
The Register
-
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
SecurityWeek
-
Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
CyberSecurityNews
-
8,539 reasons to rethink how vulnerabilities get patched
Help Net Security
-
Fighting AI With AI – The Future Of Cybersecurity
sify.com