Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News – Amit Assaraf – ESW #475
Interview - Amit Assaraf
As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation.This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them!Topic - The British Library Cyber-Attack
For this week’s topic segment, we’re discussing the British Library cyber-attack.In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library’s £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization’s tech debt comes due at once.ResourcesThe Weekly Enterprise News
Finally, in the enterprise security news,- We check the vibes
- the funding
- the acquisitions
- and the closures
- is the vulnpocalypse real, or not?
- TeamPCP finds out why being perpetually online isn’t great if you’re doing cybercrimes
- millions of IDs get leaked online
- What’s the bigger story: Huggingface and NVIDIA or Microduck?
- Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode!
Amit Assaraf is a cybersecurity innovator, entrepreneur, and the Senior Director of Product Management at Palo Alto Networks. He joined Palo Alto Networks following the acquisition of Koi, where he served as Co-founder and CEO. At Koi, Amit pioneered a new cybersecurity domain providing organizations with comprehensive visibility, assessment, and policy enforcement across all self-provisioned software. This initiative built upon his previous work with ExtensionTotal, a tool that became indispensable to top security teams for detecting and mitigating threats in third-party software extension ecosystems. Prior to founding Koi, Amit co-founded Landa, a proptech startup that democratized real estate investment, achieving significant growth and securing over $45 million in venture funding. Amit’s career began in Israel’s elite Unit 8200, where he gained extensive, foundational experience in cybersecurity.
- Security leaders, you can’t secure what you can’t see. Between cloud sprawl, SaaS, and shadow IT, most organizations don’t have a complete picture of their attack surface.So how do you measure and reduce exposure?At the Attack Surface Management Virtual Cybersecurity Summit on September 16th, learn how leading teams are gaining continuous visibility and turning unknown assets into managed risk.Security Weekly listeners can register for free at https://securityweekly.com/ASM using the promo code: CSS26-SW
- Unlock the full InfoSec World experience with the All Access Pass, featuring premium workshops, exclusive content, VIP experiences, and expanded opportunities to connect with cybersecurity leaders across industries. Join us in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Adrian Sanabria
- FUNDING/M&A courtesy of the Security, Funded newsletter, issue 259 – In Fraud We Trust
VIBE CHECK
Is the "give every defender an agent" thesis the real security unlock, or is it the wrong bottleneck?
- 46% - No - most orgs can't operationalize it fast enough to matter
- 23% - It's vendor-driven urgency, not a real gap
- 23% - No - triage judgment is the bottleneck
- 8% - Yes - coverage was always the limit
FUNDING
- Socure, a United States-based digital identity verification and fraud prevention platform, raised a $156.0M Series E from Summit Partners.
ACQUISITIONS
- NetSPI and Synack reportedly merge
- HOT RUMOR: Proofpoint in talks to acquire Varonis
- ClickHouse, a database/data warehousing company, acquired RunReveal, a security log management vendor for an undisclosed amount.
- Minimus (formerly Gutsy) and there assets thereof, an Israel-based secure-by-design container image company, was acquired by Echo for an undisclosed amount. Minimus had previously raised $51.0M in funding.
SHUTDOWNS
- Minimus, an Israel-based secure-by-design container image company, shut down operations. Its assets were sold to Echo (see above). Minimus had previously raised $51M in funding.
- HOT TAKES: Rumors of the Vulnpocalypse Have Been Greatly Exaggerated
Jeremiah and Robert have been doing some very interesting research over at Root Evidence. This webinar and the accompanying report share some interesting findings.
The most significant hot take is that the popular ZeroDayClock.com's analysis was incorrect. The key miscalculation was that time-to-exploit was using the first sign of exploitation as point A and when MITRE added the CVE to NVD as point B. The calculation does a better job of measuring how fast MITRE moves than measuring attacker exploit development speed.
ZeroDayClock.com has been wiped clean and appears to be under construction. It's unclear if this is directly tied to the release of this report, or if it is coincidental. Based on my conversations with folks in the vuln research community, I'm fairly certain Sergej Epp was aware of the alleged shortcomings of his calculations.
The silver lining is that this is what science looks like! Someone publishes something and someone else attempts to reproduce their findings and finds issues. All published out in the open, so that anyone can help and contribute to a better understanding of the state of vuln mgmt and exploitation.
- VULNERABILITIES: Everything I own, owned
On a whim, the author points AI at all the accessories connected to his computer to see if it can find significant vulnerabilities. Nothing survived unscathed.
While none of the vulnerabilities are groundbreaking, it's a sobering experiment towards validating a significant and common AI hype claim: that you can point an LLM at damn near anything and come away with vulnerabilities. There was no cherry picking here - these were literally just thing things on the author's desk.
I think this says a lot about the potential of future targeted attacks. Currently, the evidence we have says that opportunistic attacks are the majority, but if someone really wants to compromise a specific organization, it's not too farfetched to assume they'll take 3-4 hours and a few hundred dollars of tokens to find a target-specific zero-day.
- VULNERABILITIES: Thousands of Leaked AWS Access Keys Still Active
- CYBERCRIME: Unmasking TeamPCP: Software Supply Chain Attacks – Flare
These younger criminals are finding out that it's hard to not get caught when you're terminally online...
- JAILBREAKS: Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
- ESSAYS: Security Research Without Asking Permission
Neils Provos discusses his experiences kicking paid services to the curb and using open models on his own hardware to do security work. TL;DR - you can do a lot of interesting work with $10k of hardware.
- DATA LEAKS: FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security
This one is really bad, as photos of all the IDs were included in the breach. My thoughts:
- The attackers took down the site, and I'm not sure that's a good thing. It could suggest that the criminals were worried about getting too much attention from US law enforcement, OR it could suggest that one customer made an offer they couldn't refuse to sell the whole database, which required them to take it down. We've often seen criminals willing to both sell individual data records, or all the stolen data wholesale.
- This much data would have taken a long time to steal - there was definitely a detection failure somewhere.
- We don't know for sure that it was IDScan yet - I'm sure we'll learn more in the next 24-48 hours.
- If it was IDScan, this was definitely a 'you had one job' situation. Any vendor knowingly capturing millions of ID cards must assume they're painting a target on their back and should be spending a lot more resources on security compared to the average business.
- The majority of these IDs include photos. Reverse image search engines exist, that allow you to search the Internet with someone's face. With hundreds of millions of ID photos, it's possible to deanonymize people in witness protection programs, people who have changed their names or identities for any reason, discover people using fake ids, identify people with medical IDs for marijuana and other controlled substances, determine where people work (CAC cards and commercial driver licenses).
- SQUIRREL: Microduck – A tiny biped robot you can teach new tricks
- SQUIRREL: Dyson CameraJet™ electric toothbrush (Ceramic pink)
- BREACHES: Hackers push malicious Virtualizor update in BGP hijacking attack
