Cybersecurity
Journalism
May 12, 2026
The Hacker News / Dark Reading — Agentic AI Security Blind Spot

48% of security professionals rank agentic AI as the top attack vector for 2026. Most enterprise security tools cannot monitor it.

“Security teams that cannot speak the language of AI engineering get bypassed. Business units move forward without them, not out of bad faith, but because a security team that cannot engage substantively with the technology is not a useful partner.”

A SANS Institute instructor writing in The Hacker News identified three categories of agentic risk already in production: general-purpose coding agents embedded in developer workflows (whether formally approved or not), MCP-connected vendor agents that can receive and act on inputs from calendars, email, and ticketing systems (a malicious calendar invite with hidden instructions is a live attack vector), and custom agents built by anyone in the organization without writing traditional code. Most of these agents will not go through a security review before they go live. A Dark Reading poll found 48% of cybersecurity professionals rank agentic AI as the single most dangerous attack vector for 2026, outranking deepfakes and board-level cyber risks. Most enterprise SIEM and EDR tools have no native capability to monitor agentic AI behavior. An agent with access to both a terminal and an email inbox can be manipulated through either channel to act in the other. That is a lateral movement path traditional security models were never designed to handle.

48%
Security pros rank
agentic AI #1 threat
0
SIEM/EDR tools with
native agent monitoring
CISA
Issued expanding
attack surface warning
How AVAAS solves this

Security teams cannot govern what they cannot evaluate independently. If 48% of security professionals consider agentic AI their top threat and their existing tools cannot monitor it, the gap is not a monitoring problem. It is a verification problem. AVAAS certifies AI agents before they reach production by testing whether they distinguish between reversible and irreversible actions, whether their permissions compose safely across systems, and whether their behavior under adversarial conditions matches their behavior under normal operation. The PocketOS incident is exactly the kind of failure this article predicts. Independent pre-deployment certification is the intervention that catches it before it becomes a lateral movement path.

✓ Verified
Abugharbia, A. (May 12, 2026). The Hacker News / SANS Institute. thehackernews.com · Dark Reading poll (2026). kiteworks.com

This entry is one of 37 documented cases in the AVAAS evidence ledger, a public record of AI and automated-system failures with a verified source on every entry.

Every case here reached a person.

AVAAS certifies how AI systems behave at the decision point, with documented third-party evidence of conformity to a published standard.

Certify Your AI →