Adversaries hijacked AI security tools at 90+ organizations. The next wave has write access to the firewall

TL;DR AI
2 min readKey summary
Attackers used prompt injection to compromise AI security tools at more than 90 organizations, mainly for credential theft and crypto theft.
The article warns that next-generation autonomous SOC agents can do more than read data; they may change firewall rules, IAM policies, and endpoint states through approved privileged actions.
That shift from read-only AI to write-capable agents raises the blast radius from data loss to direct infrastructure manipulation if compromised.
As these systems move toward production, strong governance, privilege controls, and auditing are becoming critical.
