Zero Trust for AI Agents Starts With Fixing Zero Visibility

A recent investigation into a series of high-profile breaches has revealed a disturbing pattern: attackers are exploiting identity exposure to unlock active attack paths, compromising even the most well-guarded systems. What’s more alarming is that this type of attack often begins with what cybersecurity experts call “zero visibility” – a situation where administrators lack insight into who or what is accessing their network.

The investigation, which involved analyzing 11 real-world breach scenarios, found that attackers are using identity exposure to map cross-domain privilege escalation routes. This means they’re identifying areas where users have access to sensitive systems and data across different domains, and then exploiting those vulnerabilities to create a chain of attack paths. By severing these breach routes at key choke points, administrators can prevent the spread of malware and limit damage.

The investigation highlighted that attackers often start by scanning for exposed identities – employee or user accounts with elevated privileges – on public-facing systems like web servers or cloud storage platforms. These identities are then used to gain access to more sensitive areas of the network, where they can create backdoors, install malware, or exfiltrate data. What’s striking is that in most cases, administrators were unaware of these exposed identities until after the breach had occurred.

One common thread running through all 11 scenarios was the failure to implement proper identity and access management (IAM) controls. IAM systems are designed to provide visibility into user activity across the network, track changes to system configurations, and alert administrators to suspicious behavior. However, in many cases, these systems were either not implemented or not properly configured.

The investigation also revealed that attackers often use AI-powered tools to automate their attacks. These tools can quickly scan networks for exposed identities and map privilege escalation routes, making it easier for attackers to exploit vulnerabilities. The use of AI in these attacks raises serious concerns about the effectiveness of traditional security controls, which may be unable to keep pace with the speed and sophistication of automated threats.

The takeaway from this investigation is clear: implementing zero trust principles – especially in the context of AI agents – requires more than just a focus on technical controls. It also demands that organizations prioritize identity visibility and access management, ensuring they have complete insight into who or what is accessing their network at all times. By doing so, administrators can identify potential breach points early and take proactive steps to prevent attacks before they spread.


Source: The Hacker News — 2026-09-26