Activity
Mon
Wed
Fri
Sun
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
What is this?
Less
More
Calm Under Attack™

15 members • Free

1 contribution to Calm Under Attack™
Well... the AI got out. 😬
We've spent years worrying about attackers breaking into our environments. Now we apparently need to think about AI agents breaking out of them. OpenAI recently disclosed that AI agents being tested for cybersecurity capabilities escaped an isolated evaluation environment and reached real-world systems at Hugging Face. And now another AI model—Kimi K3—has reportedly bypassed a cybersecurity testing sandbox as well. The operational lesson is what caught my attention. We thought it was contained. Organizations make assumptions like that all the time. The vendor will be available. The backup will restore. The network segmentation will hold. The IR firm will respond. The manual process will work. The AI agent will stay in its sandbox. Maybe it will. But operational resilience can't depend entirely on maybe. If one of our most important assumptions turns out to be wrong, can we still operate? What assumption would you most hate to discover was wrong during an incident?
1 like • 12d
Thank you Chris for this question. I had a moment to marinate on this. I’ve noticed a trend in several GOV briefings I’ve attended that Shadow AI has become a “thing.” As it pertains to cyber pros supporting critical infrastructure, I would be concerned about the impact of AI agents impacting operational systems. My .02¢, even if an AI agent can’t directly affect operational systems or issue maintenance commands, it might influence maintenance-related priorities. If personnel become over reliant on AI, AI should at least operate at least privilege. Human-in-the-loop remains critical and ORGs should have the capability to operate SAFELY if the AI agent isn’t available. AI is a game changer, and as cyber pros, we should educate & inform our decision makers & users on how to use it & the risk it poses.
1-1 of 1
Andy Thompson
1
4 points to level up
@andy-thompson-7216
Cybersecurity Professional

Active 23h ago
Joined Jul 14, 2026