HomeCyber BalkansInnovator Spotlight on Morphisec in Cyber Defense Magazine

Innovator Spotlight on Morphisec in Cyber Defense Magazine

Published on

spot_img

The AI You Didn’t Approve Is Already Running In Your Environment

In the realm of cybersecurity, the prevalence of artificial intelligence (AI) agents in enterprise environments has emerged as a significant concern. Security leaders often possess clear insights into which AI vendors their organizations have meticulously vetted. They can readily deliver a list of approved vendors, thanks to systematic procurement processes and comprehensive legal reviews. Every tool on that list is generally accompanied by a risk score, rendering a semblance of control over what the organization has sanctioned.

However, a more pressing inquiry inadvertently exposes a dangerous governance gap. When asked about the AI applications actually operating on their endpoints in real time, silence commonly reigns. This lack of visibility does not bode well for Chief Information Security Officers (CISOs), as over half of organizations are currently utilizing AI agents in production, oftentimes without formal approval. Gartner projects that by 2026, 40 percent of enterprise applications will incorporate AI agents—a remarkable surge from a mere 5 percent in 2025. This paradigm shift underscores where the real risk lies: these agents operate on laptops, servers, and developer workstations—areas typically lacking adequate security oversight.

The growing reliance on AI poses immediate challenges, highlighting a new category of endpoint control that is gaining traction. Morphisec, a leading cybersecurity firm, has recently introduced its AI Usage Control module, which became generally available on July 14, 2026, and will feature prominently at this week’s Black Hat USA conference in Las Vegas.

Two Risks Wearing the Same Coat

CISOs attempting to build robust AI governance frameworks must navigate two distinct yet intertwined risks: shadow AI and compromised AI. Unfortunately, many enterprises currently approach these risks as if they were one and the same.

Shadow AI manifests in scenarios such as employees inputting confidential information into consumer chatbots, developers downloading local language models that interact outside of the corporate network, or command-line agents operating without oversight. This traffic typically does not pass through enterprise gateways, rendering it invisible to security measures and logs.

Conversely, compromised AI raises a more alarming dilemma. This scenario involves organizations that have done all the right things: formal approval for enterprise agents, granting necessary permissions, and essentially ticking all the boxes. Yet, the risk becomes apparent when an attacker hijacks one of these agents via malicious prompts or supply chain compromises. The resulting actions appear legitimate as the agent operates under the authenticated guise of its approved credentials, rendering detection nearly impossible.

Brad LaPorte, Morphisec’s Chief Marketing Officer, has expressed his unease about this predicament. He notes that the situation appears deceptively secure until it spirals into chaos. Traditional security measures, such as firewalls and EDR (Endpoint Detection and Response) tools, were designed to monitor human behavior and devices but fall short when addressing the unique challenges posed by AI processes.

The Attacks Are Already on the Record

Despite the essential role of skepticism in cybersecurity, especially with the influx of AI-related vendor marketing, it is critical to ground discussions in facts. Researchers from ESET have identified PromptLock, a strain of polymorphic ransomware, which demonstrates the malleability of AI in malicious hands. This malware operates on local endpoints and generates unique code in real time, evading conventional detection methods. Similarly, Google Threat Intelligence reported on QUIETVAULT, which exploited a compromised npm plugin to commandeer existing command-line utilities for malicious purposes.

Additionally, incidents like GTG-2002, where an autonomous agent independently conducted financial analyses and extracted ransom from multiple organizations, showcase the vast potential for AI to wreak havoc. It’s imperative to note that not every problematic instance involves an adversary; one widely-publicized example features a coding agent misinterpreting instructions and consequently wiping a production database along with its backups in a matter of seconds.

The consequences remain severe, irrespective of intent—whether through malicious intervention or inadvertent actions, the fallout can be equally devastating in terms of financial and operational loss.

Why the Existing Stack Doesn’t See This

The structural limitations inherent in existing security stacks need to be understood by CISOs. Most security tools were developed prior to the widespread adoption of AI, leading to a critical blind spot in their design. Traditional security frameworks, like CASBs (Cloud Access Security Brokers) and gateways, are incapable of monitoring local language models or similar tools that function independently from network traffic.

Endpoint detection platforms, while close to the action, face their challenges. They may recognize processes like coding assistants but often fail to differentiate between benign activities and potentially harmful ones. The inability to perform real-time intervention further exacerbates this issue.

LaPorte succinctly highlights the gravity of the situation: “You cannot govern what you cannot see.” Presently, most enterprises lack visibility into the AI operating on their endpoints, which occurs well below network boundaries.

Putting the Control Where the AI Actually Runs

In response to these pressing concerns, Morphisec’s AI Usage Control seeks to fill the existing gap. By utilizing their Morphisec Protector, already deployed across multiple systems, organizations can employ a solution that does not necessitate additional layers or changes in infrastructure.

This design effectively addresses the very limitations previously outlined; the most hazardous AI operates within local environments, often neglecting any network boundaries. With the control function residing directly on the endpoint, AI usage can be monitored and governed in real time, allowing interventions before any harmful action is executed.

Currently available, this module automatically inventories AI tools, accounts, browser extensions, and various connectors, providing a clear overview of each tool’s access privileges. This capability not only aids in compliance with regulatory standards but also empowers security teams to enforce policies and collect necessary audit trails.

The Privacy Trade-Off Most Governance Tools Get Backwards

Most AI governance tools rely on investigating content—scanning prompts and responses—which subsequently creates potential compliance risks due to the sensitive information they end up storing. Morphisec’s governance approach circumvents this pitfall by focusing on the nature of tools and data flow rather than its content.

LaPorte emphasizes this significant design decision, explaining that it simplifies compliance conversations while effectively monitoring the movement of sensitive information without compromising data integrity.

What This Means for Your Program, Practically

CISOs should initiate their governance strategy starting with an inventory of the AI agents running across their environment, including shadow AI that hasn’t gone through formal approval processes. Following this inventory, organizations must assess the blast radius of each agent to understand its reach and impact comprehensively. It will also be vital to distinguish between shadow AI and compromised AI in terms of threat modeling to ensure appropriate controls are established for each.

With that framework in place, security teams can begin to proactively develop the audit trails and enforce policies necessary for compliance purposes.

Worth Watching

As organizations grapple with AI risks, it becomes increasingly crucial to maintain awareness of evolving governance protocols. The discussions surrounding AI not only focus on monitoring existing applications but also on understanding the very fabric of how these technologies can affect operational integrity. Morphisec’s presentation at Black Hat USA 2026 encapsulates this urgency, compelling every CISO to confront the vital question: "What AI is actually running in your environment, and who—or what—is actually in control?"

Source link

Latest articles

Verification Closes the Loop – CSO Online

In today’s cybersecurity landscape, organizations often operate under the assumption that the act of...

The Original Full Disclosure Mailing List Is Active Again

Sophia Antipolis, France, August 7th, 2026, CyberNewswire In a significant announcement at DEF CON 34...

Attackers Conceal Malware Within Oracle Database Following SQL Injection Breach

Emerging Threats in Cybersecurity: A Closer Look at SQL Injection Exploits In the ever-evolving landscape...

Autonomy Is Earned, Not Claimed

In a recent analysis stemming from more than 300,000 production penetration tests (pentests), a...

More like this

Verification Closes the Loop – CSO Online

In today’s cybersecurity landscape, organizations often operate under the assumption that the act of...

The Original Full Disclosure Mailing List Is Active Again

Sophia Antipolis, France, August 7th, 2026, CyberNewswire In a significant announcement at DEF CON 34...

Attackers Conceal Malware Within Oracle Database Following SQL Injection Breach

Emerging Threats in Cybersecurity: A Closer Look at SQL Injection Exploits In the ever-evolving landscape...