Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
VentureBeat

Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict

Kayne McGladrey, an IEEE Senior Member and cybersecurity adviser, has tracked the agent identity gap across enterprises for the past year. In previous VentureBeat reporting, McGladrey described organizations as defaulting to human-style user profiles for AI agents, a practice that can lead to permission sprawl from the start. SOC 2, ISO 27001 and PCI DSS have not fully operationalized agent identities. A decision model that returns probabilities instead of prose does not map neatly onto those existing audit categories.
AI agents breached 395 organizations using credentials your IAM policy still treats as human
VentureBeat

AI agents breached 395 organizations using credentials your IAM policy still treats as human

Kayne McGladrey, senior IEEE member, independent vCISO, and author of "Cyber Risk is a Myth," told VentureBeat that the privilege problem predates agents by decades. “We’ve had this pattern for 40-plus years,” McGladrey said. “Take this user account and clone it to that user account. We’re now doing that with agentic systems, except it’s an agent, not a human, and as we’ve seen with agentic AI, it does whatever it needs to do to get its job done, and sometimes that uses far more permissions than it should.”
Warning! Your iPhone’s Notifications Are Full of Sensitive Info—Here’s How to Make Sure It Doesn’t End Up in the Wrong Hands
Reader's Digest

Warning! Your iPhone’s Notifications Are Full of Sensitive Info—Here’s How to Make Sure It Doesn’t End Up in the Wrong Hands

Push notifications can give “a preview into people’s lives that they don’t really think about and that they don’t know they’re inadvertently disclosing,” McGladrey says. That’s because these notifications typically show the exact text of whatever message or email you’ve received. There’s no censor.
Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results
VentureBeat

Nobody can compare the security-AI numbers CrowdStrike, Google, Palo Alto and Microsoft published, including the CISOs who are stuck with the results

McGladrey offered a blunter test for CISOs weighing the decision. Most victims of AI-driven attacks, he said, "were losing to basic cybersecurity hygiene failures long before the swarms of agents arrived." His advice was to identify key business systems and the technical risks to those systems, and to close those gaps before buying the next generation of AI tooling.
Weekly Intelligence Brief — September 13, 2026
The State of the Threat

Weekly Intelligence Brief — September 13, 2026

Twenty-five years after 9/11, the systems built to make sense of instability are running lighter just as instability stacks up. The lead this week is the...
Security vendors use AI to rank Patch Tuesday CVEs — and rarely tell customers
VentureBeat

Security vendors use AI to rank Patch Tuesday CVEs — and rarely tell customers

“The vendor owes their customers one page, in writing, before a single priority task lands in anyone’s queue,” McGladrey wrote in an email to VentureBeat. “That page should cover where the model sits in the pipeline, whether deterministic code parses the CVEs or the LLM does the counting, who reviewed the output, and what fraction of a 400-row list got verified against the source rather than skimmed.”
Cyber Sidekicks: The Open-Weight Liability Trap: Who Pays When AI Fails?
Richmond Advisory Group

Cyber Sidekicks: The Open-Weight Liability Trap: Who Pays When AI Fails?

In Episode 84, fractional CISO, risk governance expert, and author Kayne McGladrey returns to the show to discuss the complex and rapidly evolving legal and financial realities of AI liability.
Don’t Sleep on Cyber
COMPOUNDINGS - The Magazine Of The Independent Lubricant Manufacturers Association

Don’t Sleep on Cyber

McGladrey said access can also be a problem, noting that the Verizon report flagged third-party involvement as contributing to 61% of manufacturing breaches. "Think about always-on VPN credentials issued to equipment vendors years ago that nobody has thought about since the equipment went on the shop floor," McGladrey said.
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
VentureBeat

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

That 3% has a reason, Kayne McGladrey, author of the forthcoming "Cyber Risk is a Myth" and a senior IEEE member, told VentureBeat during a July interview. "It's only those well-resourced companies that are above the poverty line that have met all the prerequisites," he said.
Protecting your business from rogue bots — a new CIO risk
TechTarget

Protecting your business from rogue bots — a new CIO risk

If a multi-billion-dollar frontier lab can't keep its own models contained during controlled testing, why would you trust your dev team's implementation of an open-weight model? - Kayne McGladrey, fractional CISO
AI Agents Are Buying Things Online. Those Setting The Rules Aren’t Govt. Regulators.
International Business Times

AI Agents Are Buying Things Online. Those Setting The Rules Aren’t Govt. Regulators.

McGladrey walks through how that fails in practice. An agent told to "retrieve the market data report," he explains, could use an unauthenticated connector to skip the payment handshake, hand a fraudulent report to a paying client, and, under a deferred-settlement model that x402 supports, keep the discrepancy hidden until batch reconciliation shows a valid signature that delivered the wrong resource.
The fix for the AI agent that hijacked a company’s DNS: it can propose the change, but it can’t approve it
VentureBeat

The fix for the AI agent that hijacked a company’s DNS: it can propose the change, but it can’t approve it

Almost nobody has built it. Kayne McGladrey, a senior member of the IEEE, has argued for years that an AI deployment needs a hard governance threshold, a named human holding a kill switch and a way to roll back. Asked whether any Fortune 500 company runs that, he was blunt. “I haven’t seen it done, and no, they haven’t come out and publicly said it,” McGladrey told VentureBeat.
Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.
VentureBeat

Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.

"Kayne McGladrey, an IEEE senior member who advises enterprises on risk, put the funding logic bluntly in an interview with VentureBeat. “Anything that seems to have a cybersecurity flavor is generally put into the cybersecurity risk category, which is a complete fiction,” McGladrey said. “They should be focused on business risks, because if it doesn’t affect the business, like a financial loss, then nobody’s going to pay attention to it, and they will not budget it appropriately.” A rank number from a 29-person vote is a weaker budget argument than the business system the agent touches."
Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn’t tell users what they’d done
VentureBeat

Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn’t tell users what they’d done

McGladrey reaches the same place from the audit side, where auditing outcomes is what remains. “We can audit code for compliance. We can audit code for security. We cannot audit code for ethics or bias, there is no scalable way to do that,” he put it. “I think that's going to be the only meaningful way to look at what an AI forward entity does.”
Grok 4.6 Arrives as SpaceX Claims All Employee Work as AI Training Material
Tech Times

Grok 4.6 Arrives as SpaceX Claims All Employee Work as AI Training Material

Kayne McGladrey, a senior member of the IEEE, has noted the structural distinction that explains why this matters for agent models specifically: "synthetic data lacks the unpredictability of human responses to the unexpected, such as when a window moves or is resized," and behavioral training data is what teaches a model "how tools flow together."
AI-Enabled Ghost Student Fraud: How IT Leaders Are Fighting Back
EdTech Magazine

AI-Enabled Ghost Student Fraud: How IT Leaders Are Fighting Back

“If you look at the successful investigations over the past five years, there’s been about $350 million in ghost student schemes that have been thwarted,” says Kayne McGladrey, a cybersecurity risk adviser and senior member of IEEE, a nonprofit professional organization that champions technical innovation.
What does a data breach cost? AI is a sizable factor
CSO Online

What does a data breach cost? AI is a sizable factor

Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and independent virtual CISO. “Treat your models and their APIs like crown jewels,” says McGladrey. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?”
The Shai-Hulud npm worm didn’t fake its security check — it earned a legitimate one
VentureBeat

The Shai-Hulud npm worm didn’t fake its security check — it earned a legitimate one

The pressure to fix this will not come only from threat reports. It is about to come through contracts. Kayne McGladrey, a senior member of the IEEE, told VentureBeat in an exclusive interview that enterprises are starting to push software security obligations onto the vendors and maintainers in their supply chains. "We're going to start seeing companies trying to contractually shift liability to other parties in their supply chain," he told VentureBeat. "We're using your technology, but we want you to do the security for it."
TechRound is excited to announce the winners of our HealthTech44 2026!
TechRound

TechRound is excited to announce the winners of our HealthTech44 2026!

As an independent virtual CISO with a background in risk management, cybersecurity, and regulatory compliance, I prefer facts over marketing claims. For TechRound’s HealthTech44 2026, I ranked the submissions on five evidence-based dimensions: stated security maturity, AI claim substantiation, clinical validity, patient impact, and the team’s credibility. Companies that scored higher had provided named certifications, published benchmarks, regulatory clearance, quantified outcomes, and experienced clinical leaders named in their submission. By comparison, entries with visible AI instructions, placeholder content, or contradictory claims were disqualified, and submissions that were primarily unsubstantiated product marketing ranked poorly with me.
New ransomware targets AI model weights and can’t even collect the ransom
VentureBeat

New ransomware targets AI model weights and can’t even collect the ransom

That figure makes the argument fundable. Kayne McGladrey, an IEEE Senior Member who has spent his career in identity security, told VentureBeat that security teams lose these fights by filing the exposure under the wrong heading. Companies "should be focused on business risks rather than some, you know, cybersecurity risk, because if it doesn't affect the business, like a loss or financial loss, in this case, predominantly, then nobody's going to pay any action to it, and they will not budget it appropriately, nor will they adequately put in controls to prevent it," he said. A destroyed model carries a known replacement cost, which is the version of this story a CFO acts on.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.