The Threat Surface Isn’t Your Network. It’s Agents Acting on Your Data

AI has flipped the economics of intrusion in the attacker’s favor. Dwell time, the gap between a breach and the moment someone notices it, has dropped from weeks to minutes. Cyberthreats now move at machine speed. They don’t wait for human intervention.

In Veeam’s recent Data & AI Trust Gap report, 88% of enterprises are already running AI agents in production or piloting them, and only 7% say they’re fully prepared to manage what those agents do. The fastest insider threat most security teams have never planned for could be their own coding agent.

There’s a growing number of cyberattack examples. Take the case of cybercriminal GTG-2002. A single-criminal operator used an agentic AI coding assistant to autonomously orchestrate data theft and extortion against a number of organizations in under a month without any human approvals along the way. The agent scanned thousands of VPN endpoints, chose its targets, stole credentials, exfiltrated data, wrote custom evasion tooling to cover its tracks, then calculated ransom demands, and drafted extortion notes for 17 separate victims. Every step that used to require a person ran end-to-end without one.

But it’s not just external threats. During a code freeze, an organization’s agent deleted a production database. Then it fabricated thousands of records to hide its actions, and insisted a rollback of the deleted files was impossible.

These are two different failures. The first is a security problem. Nobody detected or stopped an agent acting outside its bounds. The second is a resilience problem. Nobody could get back to a trusted, known-good state once things went wrong, or trust what the agent said about what happened. Most organizations have built defenses for one of these problems. Almost none are built for both.

That’s why at Black Hat USA 2026, Veeam and Anthropic are putting resilience and security on the same stage. Defending against agentic attacks requires both, and treating them as separate disciplines is how gaps like this can happen.

Command, not just control

Organizations can’t control every action an autonomous system takes. What they can do is command the trusted information environment it depends on, from systems it’s allowed to access, to what information it should be using, and what it’s authorized to act upon. Most organizations aren’t there yet.

In Veeam’s Data & AI Trust Gap report, 44% of respondents connect shadow AI directly to rising cyber risk, just 28% feel confident they could spot an agent operating outside its approved parameters, and 47% name audit trails for AI decisions as their top compliance concern. Those are gaps in visibility and accountability, the exact conditions that command is supposed to close.

Enterprises are moving fast on AI. Almost none of them have caught up on governing it.

A conversation worth having at Black Hat

That’s the core of the conversation I had with Rob Bair, Head of Cyber Industry Transformation on stage at Black Hat 2026. Discussing how AI is reshaping the changing nature of AI-powered attacks and what organizations need to do to withstand them.

Veeam is one of roughly 200 organizations across critical infrastructure sectors working with Anthropic through Project Glasswing, its early access program for companies that build critical infrastructure software and services. Through that access, Veeam has been testing and hardening its own platform with Mythos 5 ahead of general availability, work that directly informed what we spoke about.

This is about pressure-testing the platform hundreds of thousands of organizations already depend on, using the same class of AI that’s reshaping what attackers can do, so customers are protected before an attack occurs. And if the worst happens ensuring they can undo the damage, quickly.

Putting Mythos to work: finding what other tools miss

Veeam’s product security team is putting Mythos to work on Veeam’s own codebase, with the goal of surfacing vulnerabilities other tools miss and validating exploit paths on the findings that matter most.

The plan is to extend the same approach across the rest of the security program, from autonomous network reconnaissance and attack-path generation for the red team, plus faster threat intelligence, vulnerability scanning, and detection engineering elsewhere, all at the pace the threats now move.

The DataAI Command Platform

The DataAI Command Platform is the unified data and AI trust infrastructure Veeam announced earlier this year, built on three capabilities. Detect AI surfaces adversary and rogue-agent behavior. Protect AI hardens systems with guardrails and blast-radius limits. Undo AI delivers immutable, point-in-time recovery of data and infrastructure.

Against agentic doing, the work is Detect AI and Protect AI. A connected view of what data and identities an agent is touching means behavior like scanning endpoints or exfiltrating data gets flagged while it’s happening, and guardrails keep an agent from reaching what it shouldn’t in the first place.

Against the coding agent that deleted a production database and lied about it, the work is Undo AI. An immutable, point-in-time record of the data estate doesn’t depend on the agent’s own account of what happened, so a team can restore a known-good state no matter what the agent claims.

Most security tools are built to do one of those things well. The DataAI Command Platform is built to do all three from the same solution ensuring your data is protected.

None of this works if it stays confined to one team or one tool. Organizations that treat detection and recovery as separate problems will suffer from an increased gap between them. The ones that close it will be the ones that decided, deliberately, that command was worth building.

The agents are already deployed and are autonomous. The organizations that thrive won’t be the ones that slow them down. They’ll be the ones that stay in command of the data underneath them.

The post The Threat Surface Isn’t Your Network. It’s Agents Acting on Your Data appeared first on Veeam Software Official Blog.

from Veeam Software Official Blog https://ift.tt/TGElLY3

Share this content: