AI in Cybersecurity

Explore top LinkedIn content from expert professionals.

  • View profile for Rock Lambros
    Rock Lambros Rock Lambros is an Influencer

    Securing Agentic AI @ Zenity | OWASP GenAI & Agentic AI | RockCyber | Cybersecurity | Board, CxO, Startup, PE & VC Advisor | CISO | CAIO | QTE | AIGP | Author | Security Tinkerer | Tiki Tribe

    24,071 followers

    AI security/securing the use of AI is going to kill me. I use Claude Code almost daily. It's a problem.... Here's what I have to change AGAIN this week. Security researcher Ari Marzuk disclosed 30+ vulnerabilities across AI coding tools. Cursor. GitHub Copilot. Windsurf. Claude Code. All of them. He called it IDEsaster. The attack chain includes prompt injection, hijacking LLM context, and auto-approved tool calls executing without permission. Then, legitimate IDE features are weaponized for data exfiltration and RCE. Your .env files. Your API keys. Your source code. Accessible through features you thought were safe. Most studies I read claim that around 85% of developers now use AI coding tools daily. Most have no idea their IDE treats its own features as inherently trusted. 𝗦𝗼... 𝗮𝗳𝘁𝗲𝗿 𝗿𝗲𝘃𝗶𝗲𝘄𝗶𝗻𝗴 𝗔𝗿𝗶'𝘀 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵, 𝗵𝗲𝗿𝗲'𝘀 𝗜 𝘄𝗶𝗹𝗹 𝗯𝗲 𝗱𝗼𝗶𝗻𝗴... Be warned: All this is SO much easier said than done! Audit every MCP server connection. Checked for tool poisoning vectors where legitimate tools might parse attacker-controlled input from GitHub PRs or web content. Removed servers I couldn't verify. Disabled auto-approve for file writes. The attack chains weaponize configuration files and project instructions like .claude/settings.json and CLAUDE.md. One malicious write to these files can alter agent behavior or achieve code execution without additional user interaction. Move all credentials to a secrets manager. No .gitignored .env files in agent-accessible directories. API keys live in 1Password CLI. Environment variables inject at runtime through a wrapper script the LLM never sees. Start running Claude Code in isolated containers. Mounted volumes limited to specific project directories. No access to ~/.ssh, ~/.aws, or ~/.config. If the agent gets compromised, blast radius stays contained. Enable all security warnings. Claude Code added explicit warnings for JSON schema exfiltration and settings file modifications. These exist because Anthropic knows the attack surface. Add pre-commit hooks for hidden characters. Prompt injections hide in pasted URLs, READMEs, and file names using invisible Unicode. Flag non-ASCII characters in any file the agent might ingest. The fix isn't to stop using AI coding tools. The fix is to stop trusting them implicitly. What controls do you have for AI tools with write access to your codebase? 👉 Follow for more AI and cybersecurity insights with the occasional rant #AISecurity #DevSecOps

  • View profile for Andreas Horn

    Founder @ Human in the Loop | Speaker, Author, Advisor

    257,233 followers

    McKinsey & Company 𝗮𝗻𝗮𝗹𝘆𝘇𝗲𝗱 𝟭𝟱𝟬+ 𝗲𝗻𝘁𝗲𝗿𝗽𝗿𝗶𝘀𝗲 𝗚𝗲𝗻𝗔𝗜 𝗱𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁𝘀 — 𝗮𝗻𝗱 𝗳𝗼𝘂𝗻𝗱 𝗼𝗻𝗲 𝗰𝗼𝗺𝗺𝗼𝗻 𝘁𝗵𝗿𝗲𝗮𝗱: ⬇️ One-off solutions don’t scale. The most successful projects take a different path: They use open, modular architectures that enable speed, reuse, and control. → Designed for reuse → Able to plug in best-in-class capabilities → Free from vendor lock-in This is the reference architecture McKinsey now recommends — optimized to scale what works while staying compliant. It consists of five core components: ⬇️ 𝟭. 𝗦𝗲𝗹𝗳-𝘀𝗲𝗿𝘃𝗶𝗰𝗲 𝗽𝗼𝗿𝘁𝗮𝗹: → A secure, compliant “pane of glass” where teams can launch, monitor, and manage GenAI apps. → Preapproved patterns, validated capabilities, shared libraries. → Observability and cost controls built-in. 𝟮. 𝗢𝗽𝗲𝗻 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 → Services are modular, reusable, and provider-agnostic. → Core functions like RAG, chunking, or prompt routing are shared across apps. → Infra and policy as code, built to evolve fast. 𝟯. 𝗔𝘂𝘁𝗼𝗺𝗮𝘁𝗲𝗱 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗴𝘂𝗮𝗿𝗱𝗿𝗮𝗶𝗹𝘀 → Every prompt and response is logged, audited, and cost-attributed. → Hallucination detection, PII filters, bias audits — enforced by default. → LLMs accessed only through a centralized AI gateway. 4. 𝗙𝘂𝗹𝗹-𝘀𝘁𝗮𝗰𝗸 𝗼𝗯𝘀𝗲𝗿𝘃𝗮𝗯𝗶𝗹𝗶𝘁𝘆 → Centralized logging, analytics, and monitoring across all solutions → Built-in lifecycle governance, FinOps, and Responsible AI enforcement → Secure onboarding of use cases and private data controls → Enables policy adherence across infrastructure, models, and apps 5. 𝗣𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻-𝗴𝗿𝗮𝗱𝗲 𝗨𝘀𝗲 𝗖𝗮𝘀𝗲𝘀 → Modular setup for user interface, business logic, and orchestration → Integrated agents, prompt engineering, and model APIs → Guardrails, feedback systems, and observability built into the solution → Delivered through the AI Gateway for consistent compliance and scale The message is clear: If your GenAI program is stuck, don’t look at the LLM. Look at your platform. 𝗜 𝗲𝘅𝗽𝗹𝗼𝗿𝗲 𝘁𝗵𝗲𝘀𝗲 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁𝘀 — 𝗮𝗻𝗱 𝘄𝗵𝗮𝘁 𝘁𝗵𝗲𝘆 𝗺𝗲𝗮𝗻 𝗳𝗼𝗿 𝗿𝗲𝗮𝗹-𝘄𝗼𝗿𝗹𝗱 𝘂𝘀𝗲 𝗰𝗮𝘀𝗲𝘀 — 𝗶𝗻 𝗺𝘆 𝘄𝗲𝗲𝗸𝗹𝘆 𝗻𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿. 𝗬𝗼𝘂 𝗰𝗮𝗻 𝘀𝘂𝗯𝘀𝗰𝗿𝗶𝗯𝗲 𝗵𝗲𝗿𝗲 𝗳𝗼𝗿 𝗳𝗿𝗲𝗲: https://lnkd.in/dbf74Y9E

  • View profile for Sol Rashidi, MBA
    Sol Rashidi, MBA Sol Rashidi, MBA is an Influencer
    123,057 followers

    AI is not failing because of bad ideas; it’s "failing" at enterprise scale because of two big gaps: 👉 Workforce Preparation 👉 Data Security for AI While I speak globally on both topics in depth, today I want to educate us on what it takes to secure data for AI—because 70–82% of AI projects pause or get cancelled at POC/MVP stage (source: #Gartner, #MIT). Why? One of the biggest reasons is a lack of readiness at the data layer. So let’s make it simple - there are 7 phases to securing data for AI—and each phase has direct business risk if ignored. 🔹 Phase 1: Data Sourcing Security - Validating the origin, ownership, and licensing rights of all ingested data. Why It Matters: You can’t build scalable AI with data you don’t own or can’t trace. 🔹 Phase 2: Data Infrastructure Security - Ensuring data warehouses, lakes, and pipelines that support your AI models are hardened and access-controlled. Why It Matters: Unsecured data environments are easy targets for bad actors making you exposed to data breaches, IP theft, and model poisoning. 🔹 Phase 3: Data In-Transit Security - Protecting data as it moves across internal or external systems, especially between cloud, APIs, and vendors. Why It Matters: Intercepted training data = compromised models. Think of it as shipping cash across town in an armored truck—or on a bicycle—your choice. 🔹 Phase 4: API Security for Foundational Models - Safeguarding the APIs you use to connect with LLMs and third-party GenAI platforms (OpenAI, Anthropic, etc.). Why It Matters: Unmonitored API calls can leak sensitive data into public models or expose internal IP. This isn’t just tech debt. It’s reputational and regulatory risk. 🔹 Phase 5: Foundational Model Protection - Defending your proprietary models and fine-tunes from external inference, theft, or malicious querying. Why It Matters: Prompt injection attacks are real. And your enterprise-trained model? It’s a business asset. You lock your office at night—do the same with your models. 🔹 Phase 6: Incident Response for AI Data Breaches - Having predefined protocols for breaches, hallucinations, or AI-generated harm—who’s notified, who investigates, how damage is mitigated. Why It Matters: AI-related incidents are happening. Legal needs response plans. Cyber needs escalation tiers. 🔹 Phase 7: CI/CD for Models (with Security Hooks) - Continuous integration and delivery pipelines for models, embedded with testing, governance, and version-control protocols. Why It Matter: Shipping models like software means risk comes faster—and so must detection. Governance must be baked into every deployment sprint. Want your AI strategy to succeed past MVP? Focus and lock down the data. #AI #DataSecurity #AILeadership #Cybersecurity #FutureOfWork #ResponsibleAI #SolRashidi #Data #Leadership

  • View profile for Pascal BORNET

    #1 AI & Automation Thought Leader | Award-Winning Expert | Best-Selling Author | Recognized Keynote Speaker | Agentic AI Pioneer | Forbes Tech Council | 2M+ Followers ✔️

    1,542,247 followers

    🔐 “Cybersecurity has been hard for humans for a long time.” In my conversation with John Velisaris (IBM Cybersecurity Services), he captured the shift happening in security operations: AI isn’t here to replace analysts — it’s here to take over the work humans shouldn’t be doing. When Microsoft Sentinel fires an alert, their autonomous system Adam immediately acts. As John put it: “You can detect all types of cybersecurity bad things… and have Adam work on those.” One message from John stood out: Explainability is essential. “If you adopt AI for anything, tell the AI to explain why it made the decision.” And his analogy is perfect: “If Adam is a digital worker, you have to train the worker to do the work the way you want it done.” This is the future: humans orchestrate, AI executes — with clarity, speed, and transparency. 👁️Watch my full interview with John: https://lnkd.in/eQ_WkpYZ 💡Curious to learn more: https://obvs.ly/Pascal001 #IBMAmbassador #AI #CyberSecurity #ThreatDetection #AIAutomation #AgenticAI #IBM #MicrosoftSentinel #DigitalWorkers #TechLeadership

  • View profile for Jay Chaudhry
    Jay Chaudhry Jay Chaudhry is an Influencer

    CEO, Chairman & Founder at Zscaler, Inc.

    125,324 followers

    On Bloomberg, I recently addressed the narrative that AI models from Anthropic, OpenAI, and others, threaten cybersecurity companies and make their services obsolete. In fact, the opposite is true. Link to live broadcast interview: https://lnkd.in/g28yMN6z Yes, these models are powerful at finding software vulnerabilities, but here’s what’s being missed: every large enterprise already has more vulnerabilities than they can patch or fix. AI doesn’t solve that problem. It amplifies it. In the past few weeks alone, I’ve had dozens of calls with CIOs and CISOs of large enterprises. And we had several thousand security leaders join our webinar asking the same question: how do we handle this? Investors are simplifying the story, but enterprises understand the stakes. There is no silver bullet. Hide applications behind Zscaler Zero Trust Exchange so attackers can’t reach what they can’t see. Prioritize vulnerability risk. Implement Zero Trust segmentation. It’s important to remember this reality - bad actors only need to succeed once. Enterprises have to succeed every time. That asymmetry is why Zscaler has been working directly with Anthropic and OpenAI at the earliest stages, identifying vulnerabilities and hardening our platform before these models ship. It’s why we protect over 45% of the Fortune 500. And it’s why tomorrow, when others release their own frontier models, we’ll be ready. In the AI Era, a foundation built on Zero Trust has never been more essential. #Cybersecurity #ZeroTrustEverywhere #ZeroTrust #AI #AIsecurity #AgenticAI #OpenAI #Anthropic

  • View profile for Jason Saltzman
    Jason Saltzman Jason Saltzman is an Influencer

    Head of Insights @ a16z | Former Professional 🚴♂️

    39,199 followers

    The average data breach now costs $4.5M... and climbing. Security teams are short-staffed and drowning in alerts. Enter AI-augmented security operations... Startups in the SOC AI market have raised $1.1B in 2025 YTD, nearly double 2024's total. Average Mosaic scores jumped +33 points in the last year, with 19 startups in the market in the top decile of all private companies, as we see rapid scaling from pilots to production deployments. Startup market leaders: → Tines (949 Mosaic Score): No-code automation with API-first architecture deploys in <1 week vs. months for legacy SOAR. Serving 400+ enterprise customers, including GitLab and Jamf, with $271M raised. → Torq (910 Mosaic Score): Limitless integration across apps with pre-built workflow templates that reduce MTTR 3×. Serving Check Point, Lennar, and Abnormal AI.  → Abnormal AI (878 Mosaic Score): Behavioral AI detects sophisticated email attacks through machine learning vs. signature matching. $5.1B valuation with $200M revenue run rate. → BlinkOps (868 Mosaic Score): Generative AI copilot integrates best practices into automated workflows. +142 Mosaic point surge signals rapid commercial validation. → Cyberhaven (791 Mosaic Score): Data lineage maps information flow to trace security incidents to origin – critical for insider threat detection. Serving pharma and financial services with $236M raised. What separates these leaders: ↳ Pre-trained on 10M+ security incidents vs. manual playbook configuration ↳ Graph-based behavioral analytics detecting 0-day threats vs. signature matching ↳ Sub-hour MTTR vs. 73-day industry average ↳ 90%+ false positive reduction vs. 60% false positive rates in legacy SIEM ↳ Single-pane orchestration across 25+ tools vs. swivel-chair integration The incumbents are watching closely. While Microsoft, Splunk, and CrowdStrike add AI features to existing platforms, these startups are AI-native – purpose-built for autonomous investigation. As the SOC AI market matures, these AI-first architectures become attractive acquisition targets for incumbents looking to accelerate their automation roadmaps. True autonomy in security remains controversial due to liability and compliance concerns. For now, most deployments maintain human oversight, but AI-augmented SOCs now deliver 3-5× analyst productivity gains. AI is promising the path to 24/7 coverage without proportional headcount growth. Last year, cloud intrusions increased 26% and supply-chain attacks rose 156%. Enterprises can't hire analysts fast enough. These companies solving for AI-augmented SOC are building the bridge for this gap. P.S. Comment "SOC it to me" for *free* access to CB Insights' full market intelligence on the 45 companies building AI-augmented security operations.

  • View profile for Jeetu Patel
    Jeetu Patel Jeetu Patel is an Influencer

    President & Chief Product Officer at Cisco

    177,746 followers

    Alignment without context integrity is not safety. An AI agent can faithfully follow its instructions and still be dangerous if its understanding of reality is wrong. Anthropic recently disclosed that Claude models gained unauthorized access to the real systems of three organizations during cybersecurity evaluations. The agents had been told they were operating in a simulation with no internet access. But a configuration mistake gave them access to the live internet. They treated real production systems as part of the exercise and kept pursuing the goal they had been given. OpenAI separately disclosed that models found a previously unknown vulnerability, escaped an isolated evaluation environment and compromised Hugging Face. These were not simply failures of intelligence. The deeper problem was that the agents were acting inside a false understanding of reality. We have spent years asking whether an AI system will follow our instructions. We now also need to ask whether it correctly understands the environment in which those instructions are being executed. This creates a new security requirement. Context integrity. Before an agent acts, the system must continuously verify where it is, which resources are in scope, whose authority it carries, what it is allowed to do, and when that authority expires. Just in time permission for every action. At just the right time. For just enough time. Assessed in real time. Those facts cannot live only inside a prompt. They must be verified and enforced by the infrastructure around the model. A prompt is not a security boundary. Zero trust taught us to never trust identity and always verify access. And provide least privileged access. Agentic AI adds another dimension. Never blindly trust context. Continuously verify reality. The next security perimeter is not just the agent’s identity. It is the agent’s understanding of reality. The most dangerous agent may not be misaligned. It may simply be mistaken. And in an agentic world, a false belief can become a real breach.

  • View profile for Sean Connelly🦉
    Sean Connelly🦉 Sean Connelly🦉 is an Influencer

    Architect of U.S. Federal Zero Trust | Co-author NIST SP 800-207 & CISA Zero Trust Maturity Model | Former CISA Zero Trust Initiative Director | Advising Governments & Enterprises

    24,176 followers

    🚨 Zero Trust for AI Agents Anthropic just released "Zero Trust for AI Agents." As we're thinking about agentic permissions, applying a Zero Trust discipline is critical to secure adoption. AI agents interpret goals, call tools, chain actions, delegate to other agents, and maintain context across sessions. The trust surface is different. The paper introduces "least agency" — a concept that OWASP has been promoting — and the distinction from least privilege is worth sitting with. 👉 "Least privilege" asks what an identity can access. 👉 "Least agency" asks what an agent can do, under what conditions, with which tools, and with what level of oversight. Autonomous agents introduce action risk alongside access risk — and the boundaries around behavior need to be architecturally enforced, not assumed. The paper includes a design test worth writing down: 🔥 Does the control make the attack impossible, or merely tedious?🔥 The practical controls follow directly from Zero Trust fundamentals — cryptographic agent identity, short-lived credentials, tool allow-listing, sandboxed execution, and full traceability from prompt to action to outcome. None of this is new doctrine. It's existing architecture applied to a harder problem. Full disclosure: the paper cites NIST SP 800-207 on Zero Trust Architecture and the CISA Zero Trust Maturity Model, both of which I co-authored during my time supporting Federal Zero Trust efforts at CISA. Zero Trust is built for a world where we have to remove implicit trust. Agentic AI is the next version of that same problem — valid identities, valid credentials, legitimate-looking actions, and still no basis for assumed trust. Access is earned. Actions are constrained. Agency must be governed. 👉🏼 Link to Anthropic's paper in the comments.

  • View profile for Francine Katsoudas
    Francine Katsoudas Francine Katsoudas is an Influencer

    Executive Vice President and Chief People, Policy & Purpose Officer at Cisco

    65,556 followers

    When we talk about the future of AI, the conversation often centers on the speed of the technology and how much can be automated.   But there's another question we need to be asking: Are we investing as quickly in people as we are in the technology itself?   That question is especially urgent in cybersecurity. Frontier models can help teams identify threats, triage incidents, and respond faster than ever. They can also increase the speed and sophistication of attacks—raising the stakes for human oversight, experience, and judgment.   Our latest report from the AI Workforce Consortium highlights several critical shifts:   • Cybersecurity job postings requiring AI skills have doubled year over year. Yet while 40% of leaders plan to invest in AI capabilities, only 25% are prioritizing investment in the skills people will need to manage these systems.   • The talent gap is becoming an experience gap. More than 4.8 million cybersecurity roles remain open globally, while early-career workers are often expected to arrive with both AI-agent proficiency and strong human skills.   • Roles are shifting from manual execution to strategic orchestration. Supervising AI, validating its output, and applying ethical judgment are quickly becoming essential parts of the work.   Navigating this transition will require a different kind of leadership. Managers must become player-coaches—close enough to the work to guide their teams, establish clear guardrails, and help people navigate constant change. And when we are transparent about what is changing and why, we build the trust people need to experiment, learn, and innovate with confidence.   The technology will keep moving quickly. Our investment in people has to keep pace.   I invite you to explore the findings and share your thoughts: https://lnkd.in/gMX2XuX7

  • View profile for Panagiotis Kriaris
    Panagiotis Kriaris Panagiotis Kriaris is an Influencer

    FinTech | Payments | Banking | Advisor, Founder, Editor

    166,466 followers

    Banks’ biggest tech challenge isn’t upgrading legacy systems- it’s integrating an entirely new (Gen)AI layer with orchestration in the lead. And making it work across functions. Too many banks often start with the wrong focus. Whereas dealing with legacy infrastructure is inevitable, it can become a blind spot without the right understanding of what it needs to achieve. Delivering agile, intelligent services that anticipate customer needs should be the goal. Here is a high-level overview of how the back end can be adjusted: 𝟭. 𝗢𝗿𝗰𝗵𝗲𝘀𝘁𝗿𝗮𝘁𝗶𝗼𝗻 𝗲𝗻𝗴𝗶𝗻𝗲: -   An orchestration layer sits atop core systems, routing everything - from customer questions to fraud alerts - to the right AI service. -   Modern APIs abstract legacy systems into modular services, so AI features can be added or swapped without changing existing workflows. 𝟮. 𝗥𝗲𝗮𝗹-𝘁𝗶𝗺𝗲 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲: -   Real-time data feeds stream transactions, balance changes and logins as they happen. -   A unified data hub brings together customer details, activity patterns and risk ratings so every AI tool works from the same information. 𝟯. 𝗗𝗮𝘁𝗮-𝗱𝗿𝗶𝘃𝗲𝗻 𝗶𝗻𝘀𝗶𝗴𝗵𝘁𝘀: -   Requests are automatically enriched with live account balances, recent transactions and open support tickets - ensuring the AI’s output reflects up-to-date information. -   Data is fetched on demand from indexed records, so the AI stays current without the expense of retraining the entire model for every update. 𝟰. 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 & 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲: -   Data stays encrypted end-to-end, from intake to AI output. -   Automated audits flag bias and log every decision. -   Failure simulations uncover hidden risks before they impact customers. 𝟱. 𝗠𝗼𝗱𝘂𝗹𝗮𝗿 𝘀𝗲𝘁-𝘂𝗽: -   Modern interfaces turn core banking, payment and CRM systems into plug-and-play modules. -   Behind the scenes, back-end services can be updated piece by piece without interrupting the AI layer. 𝟲. 𝗜𝗻𝘁𝗲𝗴𝗿𝗮𝘁𝗲𝗱 𝗱𝗲𝗹𝗶𝘃𝗲𝗿𝘆 𝘁𝗲𝗮𝗺𝘀: -   Small, cross-functional teams manage everything from data ingestion to model deployment and monitoring. -   Defined roles and fast feedback loops keep projects compliant and focused on real customer needs. The GenAI layer doesn’t just sit on top of the existing setup – it’s a complete overhaul of the tech architecture and the business logic behind it. Opinions: my own, Graphic source: BCG 𝐒𝐮𝐛𝐬𝐜𝐫𝐢𝐛𝐞 𝐭𝐨 𝐦𝐲 𝐧𝐞𝐰𝐬𝐥𝐞𝐭𝐭𝐞𝐫: https://lnkd.in/dkqhnxdg

Explore categories