🕒 Created · Updated

Matt Hartman Warns Organizations to Treat AI Agents as Privileged Identities to Combat Expanding Cyber Attack Surfaces

Matt Hartman, former acting head of cyber for the US Cybersecurity and Infrastructure Security Agency, warns that AI agents are creating a new and growing attack surface for organizations. As AI moves from generating content to taking actions, agents are receiving access to sensitive systems and data, requiring defenders to treat every agent as a privileged identity. Hartman noted that AI-enabled social engineering attacks are increasing significantly, making traditional trust indicators less reliable. To counter these threats, experts suggest adopting agentic red teaming, where organizations use AI agents to attack their own systems. Evan Peña, co-founder of Armadin, highlighted that AI agents offer scale, expertise, and coverage that human-led assessments cannot match. Meanwhile, Rapid7's Christiaan Beek emphasized that traditional patch cycles are being overwhelmed by the volume of AI-assisted vulnerabilities. Beek argued that defenders must shift from focusing on severity scores to prioritizing exposure and reachability, as the gap between a patch existing and an exploit being weaponized has collapsed.

Sources