Sign in to baba News

The Desk, the news read to you every hour, is part of News Plus.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

↑↓ to move · ↵ to open · esc to close

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Unlimited follows
  • Alerts for what you follow (in the app)
  • Story alerts (in the app)
  • Hide read stories
  • The daily brief by email
  • Headlines side by side
  • Who reported first
  • The whole archive
  • Your reading diet
  • Duki without the daily limit
  • The Desk: the news, spoken every hour
  • Catch Me Up, and what changed since you read it
  • The Live Terminal

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

AI Agents Pose New 'Synthetic Insider Threat' to Organizations

By דיגיטל
Translated & summarized from N12 by baba
The story · English

A new report by Israeli cybersecurity firm Above Security identifies 166 ways artificial intelligence agents can pose a risk to organizations, creating a new category of threat dubbed 'synthetic insider threats.' Unlike traditional insider threats, which involved human employees with malicious intent, these AI agents operate with employee credentials and at machine speed, often without direct human oversight or interview. The report, developed by Nimr Keiss and Yonatan Malka of Above Security, highlights that AI agents can be manipulated or malfunction, leading to data breaches, unauthorized access, or system disruptions, even without malicious intent.

Data from Verizon and Palo Alto Networks indicates a significant increase in AI usage within the workplace, with 45% of employees regularly using AI tools on work devices, and a majority of this usage occurring through personal accounts. Alarmingly, only 30% of organizations maintain immutable logs of AI agent activities, meaning most AI operations are conducted under unmanaged identities and are difficult to trace. The report outlines four scenarios where AI agents can go awry: a compromised internal AI assistant, an agent tricked by hidden instructions in documents, an over-privileged personal AI tool, or a 'poisoned memory' where malicious instructions persist across sessions.

Above Security also points to five warning signs of rogue AI agents: non-human activity rates under a human identity, outbound traffic to unknown destinations, access exceeding requested permissions, discrepancies between reported success and actual system status, and a single identity operating from multiple locations simultaneously. To mitigate these risks, the company recommends assigning unique, time-limited identities to AI agents, granting permissions strictly based on task requirements rather than employee roles, treating all content read by an agent as data for processing rather than commands, requiring human approval for irreversible actions, and maintaining robust, immutable logs of all agent activities.

Guy Kozliner, CEO of Rig Security, a company that recently raised $12 million for its AI agent identity protection platform, echoed these concerns. He stated that traditional authentication methods are insufficient as AI agents can operate under legitimate employee accounts. Kozliner warned that the number of AI agents is projected to skyrocket, with Fortune 500 companies expected to deploy over 150,000 AI agents by 2028, underscoring the urgent need for organizations to establish control and oversight mechanisms for these powerful tools before their capabilities outpace management abilities.

Read the original at N12
Full coverage · 2 outlets
100% centerFirst: N12 · 4h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Ask About This Article

Duki reads it, and every newsroom on the same story, then answers with sources.

Open the live terminal