British security firm Darktrace released an AI security product to solve the agentic cybersecurity scourge while encouraging AI development.
Called Secure AI and centering around the firm’s flagship ActiveAI Security Platform, the solution promises to allow AI adoption without sacrificing guardrails. It primarily provides visibility into and analysis of information and data entered into or generated by generative AI tools, autonomous agents, AI development platforms, and shadow AI systems.
On the agentic front, Secure AI maps AI agents active across various environments, including cloud and internal systems, as well as monitoring how they interact using services such as model context protocol (MCP) servers, the so-called USB-C port for agentic AI.
The tool also evaluates AI risks in development and deployment for a shift-left posture, while tightening the screws on unknown or unvetted AI tools within an organization, otherwise known as shadow AI.
Agentic antagonists?
Darktrace’s launch follows the speedy popularity – and quick infamy – of OpenClaw, a less-than-foolproof system that lets AI agents execute, coordinate, and delegate tasks to other agents automatically. Researchers like Zenity Labs have discovered how indirect prompt injection can be used to establish persistent attacker control inside OpenClaw, while Snyk found almost 80 confirmed malicious payloads on the ClawHub registry, a central hub for discovering and installing skills for customizing OpenClaw.
In addition, SDxCentral revealed this week AI agents are sharing security evasion tips, specifically on web scraping under the cover of mobile proxies. The discovery was made on Moltbook, a forum run and used in the manner of Reddit but exclusively by agents, some of whom operate on the OpenClaw system.
In response to our report, Christian Reilly, field CTO EMEA at Cloudflare, said the emergence of a closed-loop forum where AI agents are able to swap scraping tactics is “more of a mechanized evolution of the existing arms race.”
“While it feels like the ultimate normalization of evasion, it represents the ‘added AI sheen’ phase where the volume and velocity of bot-to-bot knowledge sharing outpace human intervention," Reilly said. "[This is] the transition from static fingerprinting to defending against an ecosystem where bots autonomously learn to bypass TLS fingerprints and solve CAPTCHAs by consulting a communal database of failures and successes.”
“We should not be worried about the agents liking each other's posts,” Reilly added, “but about the security surface area. Cybersecurity researchers have already found that Moltbook’s lack of rate-limiting and its Skills framework make it a prime vector for indirect prompt injection and RCE (remote code execution). If your agent learns a scraping tip from a malicious agent on Moltbook, it might actually be downloading a script that exfiltrates your API keys.”
Jerome Segura, VP of threat research at DataDome, agreed, noting Moltbook activity represents the industrialization of evasion, confirming that traditional defenses like IP blocking are now obsolete against modern AI agents.
“By leveraging mobile 4G/5G proxies, these bots effectively hide behind legitimate human traffic, while the 'pay-per-use' x402 model removes all friction and accountability from acquiring attack infrastructure," Segura explained. "This is a hostile approach to data extraction that renders simple blocking futile; effective defense now requires analyzing behavioral intent and anomalies rather than just the source of the connection.”
The agentic threat hasn’t stopped the agentic juggernaut, though, with Darktrace joining the likes of Palo Alto Networks, which this week launched a portal to drive AI uptake among customers and partners, primarily by the use of vibe coding.
AI giant Anthropic, meanwhile, launched Claude Cowork, an agentic coding tool targeting knowledge workers not necessarily familiar with the art of code. But research from analyst house William Blair poured water on the idea that AI adoption drivers would push software vendors into obsolescence.
“Vibe coding and AI code generation certainly make it easier to build software, but the technical barriers to coding have not been the drivers of software moats for some time,” its researchers wrote. “For the most successful and scaled software companies, determining what to build next and how it should function within a broader system is fundamentally more important and more challenging than the technical act of building and coding it.”
Comments