Close Menu
NCIJ Network NCIJ Network
    What's Hot

    17 old software bugs that took way too long to squash

    August 12, 2026

    AI Hyperscalers Are Pricing Bitcoin Miners Off The Grid— Here’s Why Its A Massive Win-Win

    August 12, 2026

    Delays, biosecurity failures worsened flu outbreak at Nepal zoo, probe finds

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 17 old software bugs that took way too long to squash
    • AI Hyperscalers Are Pricing Bitcoin Miners Off The Grid— Here’s Why Its A Massive Win-Win
    • Delays, biosecurity failures worsened flu outbreak at Nepal zoo, probe finds
    • Technip Energies shaping Malaysia’s new LNG import gateway with FEED in hand
    • Farage has turned Clacton into a human zoo. Here’s the truth about what’s happening here | Sarah Elizabeth Cox
    • Solar Eclipse Live Updates: Europe Counts Down to Watch Its First Total Eclipse in Decades
    • Danube river’s low water levels reveal remains of WWII German soldiers in Hungary
    • Bridget Phillipson condemns Richard Tice’s ‘chilling attempt to silence free press’ | Richard Tice
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    The AI harness is the new attack surface

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “Teams think in terms of apps, services, pipelines, or bots,” Santos says. Harnesses disappear into code repositories, SaaS products, and vendor configuration screens instead of showing up as discrete assets in security inventories.

    Even the terminology is inconsistent.

    “One team may call something an agent, another a copilot, another a workflow assistant, another a plugin-based automation,” Santos says, “even though all of them are effectively harnesses.”

    His recommendation is to build a live inventory of every production agent, identify its harness, and map every tool and resource it can access. Then reduce those permissions to the minimum required.

    Organizations shouldn’t wait for perfect visibility. Santos estimates that 60% to 70% visibility can be achieved relatively quickly by starting with production systems, leaving prototypes and shadow AI for a second phase.

    The second problem is controlling everything the harness trusts.

    Agents don’t operate in isolation. They ingest instructions and content from tools, plugins, skills, MCP servers, websites, and other systems, often while holding credentials and permissions that let them act on behalf of users.

    Attackers therefore don’t need to compromise the model. They need to compromise something the harness is willing to trust.

    “You’re sharing your laptop with your agents, and your laptop has everything — has your identity, has your files, has your secrets,” Bargury says.

    For organizations without a dedicated AI security budget, he recommends, at minimum, running agents inside open-source containment tooling. “This is not a fix,” he cautions, “but it is helpful.”

    The size of the potential supply chain makes the problem qualitatively different from conventional software dependency management.

    “Supply chain for software is, what, 10 or 15 package registries?” Bargury says. “Supply chain for agents is any content, any image, any text, any website, any CRM object, any skill, any MCP server, any content on the internet.”

    The third problem is assuming a vendor’s security claims transfer to the environment where an agent will actually run.

    A vendor claiming it blocks 99% of prompt injections, Bargury says, may be citing “a benchmark that is not attached to reality on the ground.”

    Lasso’s findings demonstrate why that matters. Hold the model, prompt, and tools constant and change only the harness, and the security outcome can change dramatically.

    That means organizations evaluating agents may be asking the wrong question. It isn’t simply which model is safest. It’s which combination of model, harness, tools, permissions, and external inputs remains safe under the conditions in which the organization will actually deploy it.

    Meged distilled the lesson from breaking three vendors’ official automations: “Read the defaults, not the documentation.”

    “The product said it was safe,” he said, “and that’s where we started.”

    attack Harness surface
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    17 old software bugs that took way too long to squash

    Signal adds new security feature to thwart man-in-the-middle attacks

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    Microsoft releases Windows 10 KB5120249 extended security update

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    17 old software bugs that took way too long to squash

    August 12, 2026

    AI Hyperscalers Are Pricing Bitcoin Miners Off The Grid— Here’s Why Its A Massive Win-Win

    August 12, 2026

    Delays, biosecurity failures worsened flu outbreak at Nepal zoo, probe finds

    August 12, 2026

    Technip Energies shaping Malaysia’s new LNG import gateway with FEED in hand

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    17 old software bugs that took way too long to squash

    August 12, 2026

    AI Hyperscalers Are Pricing Bitcoin Miners Off The Grid— Here’s Why Its A Massive Win-Win

    August 12, 2026

    Delays, biosecurity failures worsened flu outbreak at Nepal zoo, probe finds

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.