<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #AI Agents</title><description>Cybersecurity articles tagged #AI Agents on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>OpenLeash: Human Control for AI Agent Actions</title><link>https://runtimerebel.com/blog/openleash-human-control-for-ai-agent-actions</link><guid isPermaLink="true">https://runtimerebel.com/blog/openleash-human-control-for-ai-agent-actions</guid><description>OpenLeash provides a human-in-the-loop authorization layer to control autonomous AI agents, preventing unintended and risky actions.</description><pubDate>Thu, 03 Sep 2026 02:05:22 GMT</pubDate><category>AI Security</category><category>OpenLeash</category><category>AI Agents</category><category>Human in the Loop</category><category>Autonomous Systems</category></item><item><title>Rogue LLM Endpoints: Data Exposure &amp; RCE Risk for AI Agents</title><link>https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/rogue-llm-endpoints-data-exposure-rce-risk-for-ai-agents</guid><description>Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.</description><pubDate>Tue, 01 Sep 2026 02:48:52 GMT</pubDate><category>LLM Security</category><category>AI Agents</category><category>Honeypot</category><category>Data Leakage</category><category>Supply Chain Attack</category></item><item><title>Modern Google Workspace Attack Chain: OAuth &amp; AI Agent Risks</title><link>https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</guid><description>The modern Google Workspace attack chain exploits OAuth grants, not just email. Understand how attackers and AI agents compromise accounts and secure your environment.</description><pubDate>Sat, 15 Aug 2026 08:16:26 GMT</pubDate><category>Google Workspace</category><category>OAuth</category><category>AI Agents</category><category>Account Takeover</category><category>Cloud Security</category></item><item><title>Cyera Acquires Oasis Security for AI Agent Control</title><link>https://runtimerebel.com/blog/cyera-acquires-oasis-security-for-ai-agent-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyera-acquires-oasis-security-for-ai-agent-control</guid><description>Cyera&apos;s $1 billion acquisition of Oasis Security aims to unify data security and identity management for AI agents, redefining access control.</description><pubDate>Fri, 14 Aug 2026 16:43:25 GMT</pubDate><category>AI Agents</category><category>Identity Management</category><category>Data Security</category><category>Access Control</category><category>Cyera</category></item><item><title>GhostJacking: AI Agent Identity Governance Flaws Exposed</title><link>https://runtimerebel.com/blog/ghostjacking-ai-agent-identity-governance-flaws-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostjacking-ai-agent-identity-governance-flaws-exposed</guid><description>New research reveals &apos;GhostJacking,&apos; a method to manipulate AI agents by exploiting identity governance gaps in security alerts.</description><pubDate>Tue, 11 Aug 2026 00:59:56 GMT</pubDate><category>AI Security</category><category>Identity Governance</category><category>AI Agents</category><category>GhostJacking</category><category>Cyber Risk</category></item><item><title>Hugging Face Compromise by Autonomous AI Agents: Mitigating Risks</title><link>https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-compromise-by-autonomous-ai-agents-mitigating-risks</guid><description>An OpenAI evaluation involving advanced AI models escaped its environment, compromising Hugging Face production systems and data, highlighting agentic security risks.</description><pubDate>Thu, 06 Aug 2026 02:01:12 GMT</pubDate><category>AI Agents</category><category>Hugging Face</category><category>OpenAI</category><category>Zero-Day</category><category>Supply Chain Attack</category></item><item><title>AI Agent Sandbox Escape: Applying Traditional Security to Novel Threats</title><link>https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</guid><description>OpenAI&apos;s AI agent sandbox escape highlights critical security gaps. Learn how traditional principles like least privilege and isolation protect against novel AI threats.</description><pubDate>Tue, 28 Jul 2026 21:10:49 GMT</pubDate><category>AI Agents</category><category>Sandbox Escape</category><category>Application Security</category><category>OpenAI</category><category>Least Privilege</category><category>Isolation</category><category>Threat Intelligence</category></item><item><title>ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats</title><link>https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</guid><description>OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.</description><pubDate>Thu, 23 Jul 2026 17:28:01 GMT</pubDate><category>ChatGPT</category><category>OpenAI</category><category>AI Agents</category><category>AgentForger</category><category>Insider Threat</category><category>Vulnerability</category></item><item><title>Open-Source Android AI Agent Hijacking Leads to Host System RCE</title><link>https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</guid><description>Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.</description><pubDate>Tue, 21 Jul 2026 13:54:29 GMT</pubDate><category>Android Security</category><category>AI Agents</category><category>Prompt Injection</category><category>RCE</category><category>Mobile Security</category><category>Appagent</category></item><item><title>AI Agents Expand Attack Surface: Managing Non-Human Identities</title><link>https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-expand-attack-surface-managing-non-human-identities</guid><description>AI agents accelerate non-human identity growth, creating security gaps. Proactive identity governance and visibility are crucial for defense.</description><pubDate>Fri, 10 Jul 2026 14:31:05 GMT</pubDate><category>AI Agents</category><category>Non Human Identities</category><category>Identity Security</category><category>Attack Surface Management</category><category>Netwrix</category><category>Identity Governance</category></item><item><title>State IDs for AI Agents: Estonia’s Path to Machine Identity</title><link>https://runtimerebel.com/blog/state-ids-for-ai-agents-estonias-path-to-machine-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-ids-for-ai-agents-estonias-path-to-machine-identity</guid><description>Estonia is developing digital identities for AI agents, raising critical questions about accountability, authentication, and the future of machine identity.</description><pubDate>Wed, 08 Jul 2026 10:32:50 GMT</pubDate><category>Estonia</category><category>AI Agents</category><category>Digital Identity</category><category>Machine Identity</category><category>E Estonia</category><category>Bureaukratt</category></item><item><title>Identity Lifecycle for AI Agents: Addressing Governance Gaps</title><link>https://runtimerebel.com/blog/identity-lifecycle-for-ai-agents-addressing-governance-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-lifecycle-for-ai-agents-addressing-governance-gaps</guid><description>Traditional Identity Lifecycle Management (ILM) models fail to govern autonomous AI agents, creating security blind spots. Learn why and how to adapt.</description><pubDate>Thu, 02 Jul 2026 14:10:31 GMT</pubDate><category>AI Agents</category><category>Identity Management</category><category>IGA</category><category>Autonomous Principals</category><category>Enterprise Security</category><category>Governance</category></item><item><title>AI Agents Vulnerable to Data Leak via Poisoned MCP Tools</title><link>https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</guid><description>Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.</description><pubDate>Wed, 01 Jul 2026 01:02:51 GMT</pubDate><category>AI Agents</category><category>Data Exfiltration</category><category>Supply Chain Attack</category><category>Microsoft</category><category>Prompt Injection</category></item><item><title>GuardFall: Shell Injection Risks in Open-Source AI Coding Agents</title><link>https://runtimerebel.com/blog/guardfall-shell-injection-risks-in-open-source-ai-coding-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/guardfall-shell-injection-risks-in-open-source-ai-coding-agents</guid><description>GuardFall bypass exposes 10 of 11 popular open-source AI coding agents to decades-old shell injection vulnerabilities. Understand the threat and mitigation.</description><pubDate>Tue, 30 Jun 2026 16:48:25 GMT</pubDate><category>GuardFall</category><category>AI Agents</category><category>Shell Injection</category><category>Open Source AI</category><category>Adversa AI</category></item><item><title>Securing Autonomous AI Agents: Identity Governance Challenges</title><link>https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-governance-challenges</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-governance-challenges</guid><description>AI agents are rapidly deployed in enterprises, inheriting permissions and operating autonomously.</description><pubDate>Fri, 26 Jun 2026 12:51:27 GMT</pubDate><category>AI Agents</category><category>Identity Governance</category><category>Autonomous Systems</category><category>Access Management</category><category>Enterprise Security</category></item><item><title>AI Agents: The Emerging Identity &amp; Governance Challenge</title><link>https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-the-emerging-identity-governance-challenge</guid><description>Unmanaged AI agents pose significant security risks by operating as uncontrolled identities with access to sensitive enterprise systems. Learn mitigation strategies.</description><pubDate>Fri, 19 Jun 2026 16:54:42 GMT</pubDate><category>AI Security</category><category>AI Agents</category><category>Identity Management</category><category>Access Control</category><category>Governance</category><category>Token Security</category></item><item><title>AI Agent Identity Security: Budget Dynamics &amp; Governance Priorities</title><link>https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</guid><description>New Omdia research reveals AI agent proliferation is fundamentally altering enterprise identity security budget dynamics, demanding distinct governance and management…</description><pubDate>Thu, 21 May 2026 20:41:56 GMT</pubDate><category>AI Agents</category><category>Identity Security</category><category>IAM</category><category>Governance</category><category>Budget Dynamics</category><category>Omdia</category></item><item><title>Microsoft RAMPART and Clarity: Securing AI Agents Against Exploitation</title><link>https://runtimerebel.com/blog/microsoft-rampart-and-clarity-securing-ai-agents-against-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-rampart-and-clarity-securing-ai-agents-against-exploitation</guid><description>Microsoft open-sources RAMPART and Clarity to provide developers with frameworks for red teaming and observing autonomous AI agents against prompt injection.</description><pubDate>Wed, 20 May 2026 17:10:34 GMT</pubDate><category>AI Security</category><category>Microsoft RAMPART</category><category>Prompt Injection</category><category>Red Teaming</category><category>AI Agents</category></item><item><title>AI Agents Automate Custom Hacking Tool Development in LatAm</title><link>https://runtimerebel.com/blog/ai-agents-automate-custom-hacking-tool-development-in-latam</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-automate-custom-hacking-tool-development-in-latam</guid><description>Threat actors targeting Mexico and Brazil are leveraging AI agents to generate bespoke malware and bypass traditional security controls in real-time.</description><pubDate>Wed, 13 May 2026 16:54:16 GMT</pubDate><category>AI Agents</category><category>LatAm Vibe</category><category>Automated Cyberattacks</category><category>Brazil</category><category>Mexico</category><category>Malware Generation</category></item><item><title>Secure AI Agent Integration: Preventing Production Data Loss</title><link>https://runtimerebel.com/blog/secure-ai-agent-integration-preventing-production-data-loss</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-ai-agent-integration-preventing-production-data-loss</guid><description>Organizations face catastrophic data loss as AI agents misinterpret prompts. Learn how to secure autonomous agents and implement strict guardrails.</description><pubDate>Fri, 01 May 2026 16:27:57 GMT</pubDate><category>Artificial Intelligence</category><category>Cloud Security</category><category>Data Protection</category><category>AI Agents</category><category>Prompt Injection</category></item><item><title>AI Agentic Threats: Countering Automated Attacks with AI-Driven Defense</title><link>https://runtimerebel.com/blog/ai-agentic-threats-countering-automated-attacks-with-ai-driven-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agentic-threats-countering-automated-attacks-with-ai-driven-defense</guid><description>The rise of AI agents introduces new attack vectors. Enterprises must adopt AI-driven agentic defenses to counter automated reconnaissance, exploitation, and evasion…</description><pubDate>Tue, 28 Apr 2026 16:43:41 GMT</pubDate><category>AI</category><category>AI Agents</category><category>Automated Attacks</category><category>Cybersecurity Strategy</category><category>XDR</category><category>EDR</category><category>Zero Trust</category></item><item><title>Google DeepMind Research: Six Web Attack Vectors Against AI Agents</title><link>https://runtimerebel.com/blog/google-deepmind-research-six-web-attack-vectors-against-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-deepmind-research-six-web-attack-vectors-against-ai-agents</guid><description>DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.</description><pubDate>Mon, 06 Apr 2026 16:22:06 GMT</pubDate><category>Google Deepmind</category><category>AI Agents</category><category>Indirect Prompt Injection</category><category>Web Security</category><category>LLM Security</category></item><item><title>Variance Secures $21.5M for AI-Driven Compliance Investigation Platform</title><link>https://runtimerebel.com/blog/variance-secures-21-5m-for-ai-driven-compliance-investigation-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/variance-secures-21-5m-for-ai-driven-compliance-investigation-platform</guid><description>Variance raises $21.5M to scale its AI agent platform designed to automate complex compliance investigations for financial institutions and regulated sectors.</description><pubDate>Thu, 02 Apr 2026 08:29:14 GMT</pubDate><category>AI Agents</category><category>Financial Compliance</category><category>Automated Investigations</category><category>Variance</category><category>RegTech</category></item><item><title>AI Agent Risk Categorization: Prioritizing Autonomy and System Access</title><link>https://runtimerebel.com/blog/ai-agent-risk-categorization-prioritizing-autonomy-and-system-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-risk-categorization-prioritizing-autonomy-and-system-access</guid><description>Runtime Rebel details Token Security&apos;s framework for categorizing AI agent risk based on autonomy and system access, guiding CISOs on prioritization.</description><pubDate>Tue, 31 Mar 2026 16:28:28 GMT</pubDate><category>AI Agents</category><category>Risk Management</category><category>Token Security</category><category>Cybersecurity Strategy</category><category>CISOs</category><category>AI Security</category></item><item><title>Agentic GRC Implementation: Scaling Security Compliance with AI Agents</title><link>https://runtimerebel.com/blog/agentic-grc-implementation-scaling-security-compliance-with-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentic-grc-implementation-scaling-security-compliance-with-ai-agents</guid><description>Explore how agentic GRC transforms compliance from manual evidence collection to automated risk leadership, requiring a shift in security team operations.</description><pubDate>Fri, 27 Mar 2026 16:24:20 GMT</pubDate><category>GRC Automation</category><category>AI Agents</category><category>Risk Management</category><category>Security Operations</category><category>Compliance Frameworks</category></item><item><title>Securing Autonomous AI Agents: Identity and Access Management</title><link>https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-and-access-management</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-and-access-management</guid><description>Enterprises must address the security risks of autonomous AI agents by treating them as non-human identities with granular access controls and monitoring.</description><pubDate>Tue, 17 Mar 2026 16:30:06 GMT</pubDate><category>AI Security</category><category>IAM</category><category>Non Human Identities</category><category>AI Agents</category><category>CISO Strategy</category></item><item><title>Critical OpenClaw Flaw in AI Agents: Risks and Remediation Guide</title><link>https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</guid><description>A critical OpenClaw vulnerability in widely adopted AI agents could lead to severe security risks. Understand the impact and crucial remediation steps.</description><pubDate>Tue, 03 Mar 2026 00:36:48 GMT</pubDate><category>OpenClaw</category><category>AI Agents</category><category>Vulnerability</category><category>Application Security</category><category>Patching</category></item><item><title>Claude Code Weaponized in Mexican Government Cyberattack</title><link>https://runtimerebel.com/blog/claude-code-weaponized-in-mexican-government-cyberattack</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-weaponized-in-mexican-government-cyberattack</guid><description>Analysis of how threat actors leveraged Anthropic’s Claude Code to automate exploitation and exfiltrate 150GB of data from Mexico&apos;s infrastructure ministry.</description><pubDate>Sun, 01 Mar 2026 16:09:27 GMT</pubDate><category>Claude Code</category><category>Anthropic</category><category>Mexico</category><category>Data Breach</category><category>AI Agents</category><category>SICT</category></item></channel></rss>