You spent a decade fighting over who gets a privileged account. Then a now-patched AWS Bedrock AgentCore bug, dubbed AgentCorruption, showed that one AI chatbot prompt could take over an organization’s cloud fleet. Same week, lawmakers warned that Spirit Airlines’ $10 million AI training deal could hand Google about 100 million emails, 500 million Microsoft Teams messages, employment contracts, timecards, payroll, and tax files. That pairing is the new shape of cybersecurity risk: a non-human identity with too much power, and a “business transaction” that walks your inbox out the door.

Nobody in your change-advisory board scheduled this. It arrived as a product feature and a bankruptcy exhibit.

One prompt just walked into admin

AgentCorruption is the kind of bug that makes experienced operators go quiet for a second. Not because prompt injection is new. Because the blast radius is the fleet, not a chat window. If an attacker can steer one agent into the privileges of every other agent, you’ve built a domain controller out of a conversational UI.

Your firewall still sees allowed HTTPS to a cloud API. Your brute-force alerts still watch the VPN. Neither of those is where this fight happens. The agent already authenticated. The session already looks like work. Threat-protection stacks that hunt malware droppers will miss a tool call that assumes a role, lists buckets, and keeps going.

Person using an AI chatbot on a laptop in an office
A chatbot with cloud tools is a privileged session. Treat the prompt path like you’d treat a jump host.

That’s a service account with better manners. It has a name like “assistant” so people skip the access review. It has a token that never takes vacation. It can call the same APIs your senior admins use, minus the awkward ticket that used to slow them down.

Defense in depth still works here, if you apply it to the agent the way you apply it to a CI runner. Separate the chat frontend from the identity that can mutate production. Split tool permissions so a summarizer cannot assume an org-wide role. Require a human-gated path for anything that creates users, attaches policies, or reaches a second account. If the model can do it in one hop, an attacker with a prompt can too.

AWS patched this one. Your copy-paste of the same pattern on a homegrown agent runtime is still sitting in a repo somewhere, smiling in the architecture deck.

Selling the inbox still counts as leaving

Rep. Steven Horsford’s warning on the Spirit deal is easy to file under “politics vs. tech.” Don’t. Read the inventory. Email. Teams. Contracts. Timecards. Payroll. Tax. That’s the corpus an incident responder would kill for after a breach, except here the proposed path is a purchase order.

Cyber security teams have spent years training staff not to forward payroll files to a personal Gmail. Then finance and legal discover a $10 million line item that does the same thing at company scale, with a press-friendly label: training data. You can encrypt the laptop and still lose the archive if the archive is the product being sold.

Spirit Airlines aircraft at a gate
A training deal that includes mail, chat, and payroll is an authorized bulk export. Your DLP program either covers it or it’s theater.

Ask the ugly questions before the binder goes to a buyer. Who strips credentials, SSO cookies, and password-reset threads from those mailboxes? Who redacts customer PII that employees pasted into Teams because the ticketing tool was slow? Who attests that tax records and employment contracts are out of scope? If the answer is “the model vendor will handle minimization,” you’ve outsourced your crown-jewel handling to a party that wants more text, not less.

This is also a threat detection problem hiding in records retention. Bulk export of mail and chat should page the same people who get paged for a giant S3 sync. If your only alert for “500 million messages leaving” is a signature block on an asset-purchase agreement, attackers and acquirers are using the same blind spot.

The cybersecurity work your agents actually need

Skip the strategy offsite. You already know the controls. You used them on jump hosts, CI jobs, and vendor VPNs. Apply them to anything that can call a tool on a user’s behalf.

Do this in the next change window, then keep doing it every time someone “just enables Copilot” in a side channel:

  • Inventory every agent, coding assistant, and model connector that holds a cloud, SaaS, or repo token. Name an owner. Record the role, the tools it can invoke, and whether a human has to approve mutating actions. If it isn’t in the identity inventory, it isn’t in production, even if developers swear it’s a personal utility.
  • Cut the privilege to the job. Kill wildcard IAM, unused tools, cross-account assume-role, and any path that lets one agent session mint or steer another. Security hardening here is boring on purpose: separate read tools from write tools, and keep org-wide admin off the conversational identity.
  • Ship transcripts, tool calls, and the model-connector host into the same log pipe as bastions. Retention should match privileged-session policy. If you can’t answer “what did the agent do at 14:03,” you don’t have incident response for this class of identity.
  • Treat training dumps, e-discovery exports, and “we’ll just send the PST” requests as bulk exfil until legal and security both sign a scoped manifest. Block default inclusion of payroll, health, auth mail, and customer attachments.
  • Hunt long-lived agent tokens, secrets in local chat history, and clients that store full threads on disk. Rotate on a schedule you’d use for a service principal, not a chatbot experiment.

Ongoing work is uglier than the patch. Recertify agent roles monthly. Watch for new MCP-style tool bridges the same way you watch for new OAuth apps. Put a rate limit and an allowlist around what the agent can invoke, even after a “successful” login. You already do that for admin APIs. The prompt is an admin API with a friendlier parser.

When a perfect lockout would stop payroll, take the Talos view: keep the checks printing, then constrain the path. Disable the dangerous tools. Put the agent on a dedicated identity in a dedicated account. Mirror production data only if you must, and never with live secrets. Availability is not an excuse to leave org-wide keys on a chat runtime.

If you can’t replay the chat, you didn’t investigate

SANS instructors just updated FOR577 with a day of investigating AI usage, covering the assistants your developers already installed: Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, Qwen Code, plus the ones people run because they’re bored, like OpenCode and Hermes. The interesting part isn’t the brand list. It’s that responders needed new scripts to find where the chat history even lives.

Abstract threat intelligence graphic used in a Talos newsletter
Operations still wins. If you can’t patch the agent stack today, you can still isolate it, log it, and keep the business path alive.

That’s your tell. You’ve allowed a privileged operator onto endpoints and cloud consoles, and its diary is in a JSON file under a hidden directory nobody backing up the SIEM has heard of. Classic IR assumed a human typed into a shell. These clients type for the human, cache the plan, and sometimes store secrets in the same thread as the bug fix.

Build the collection step now, while you’re calm. Know the local paths. Know the cloud audit events for tool invocation. Know whether the vendor retains prompts. Know whether a laptop reimage wipes the only copy of what the agent did to prod. If your playbook starts at “pull EDR process trees” and stops there, you’ll reconstruct the IDE and miss the session that created the IAM user.

Pierre’s Talos note is the adult supervision this week needs. Real environments run messy. You will have an unpatched agent host, a bankruptcy data request, and a developer who installed a CLI on Friday. Your job is still to keep the business alive without handing the keys to a prompt or a training corpus. Log the bot. Scope the bot. And stop selling the mailbag because someone called it innovation.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.