Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

AI Agents Pose New 'Synthetic Insider Threat' to Organizations

By דיגיטל
Translated & summarized from Mako by baba
The story · English

A new report by Israeli cybersecurity firm Above Security identifies 166 ways artificial intelligence agents can become an internal threat to organizations, a phenomenon they term 'synthetic insider threat.' Unlike traditional insider threats, which involved human employees with malicious intent, these AI agents operate with employee credentials and at machine speed, posing a significant and often undetected risk.

The report, developed by Nimr Qis, Head of AI Research, and Yonatan Malka, Head of Solutions at Above Security, highlights that AI agents can be manipulated or malfunction without malicious intent, leading to data breaches or unauthorized actions. Data from Verizon and Palo Alto Networks indicates a rapid adoption of AI by employees, with 45% regularly using AI tools on work devices, often through personal accounts, and a lack of robust logging by most organizations, making it difficult to track AI activity.

Above Security outlines four scenarios where AI agents can go rogue: a compromised internal AI assistant, an agent tricked by hidden instructions in documents, an AI tool with excessive permissions, a 'poisoned memory' where malicious instructions persist, and an agent misinterpreting commands literally. Warning signs include non-human activity rates, data exfiltration to unknown destinations, access beyond granted permissions, discrepancies between reported and actual outcomes, and a single identity operating from multiple locations simultaneously.

To mitigate these risks, Above Security recommends assigning unique, time-limited identities to AI agents, granting permissions strictly based on the task at hand, treating all content read by AI as data rather than commands, requiring human approval for irreversible actions, and maintaining immutable logs of all AI activities. They also suggest revoking an agent's permissions rather than immediately disabling the employee's account during an incident.

Meanwhile, Guy Kozliner, CEO of Rig Security, another Israeli cybersecurity firm that recently raised $12 million, emphasizes that traditional authentication methods are insufficient. He warns that AI agents, even when legitimately accessed by an employee, can exploit broad permissions to cause significant damage, potentially creating backdoors for attackers. Kozliner projects a dramatic increase in AI agents within organizations, with Fortune 500 companies expected to run over 150,000 AI agents by 2028, underscoring the urgent need for organizations to develop robust control mechanisms.

Read the original at Mako
Full coverage · 2 outlets
100% centerFirst: Mako · 4h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal