Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
AI is not an insider in the human sense, but it can help an attacker become one—and it can give software agents access and authority that once belonged to employees. At Black Hat USA 2025, CrowdStrike’s account of a North Korean-linked fake-worker campaign illustrated the first risk. The rise of agents connected to company systems illustrated the second. By 2026, CrowdStrike was also reporting malicious prompt injection targeting organizations’ AI tools. The practical lesson is to treat people, applications and agents as identities whose access must be limited, monitored and revocable.
What Black Hat 2025 revealed
Black Hat USA 2025 took place in Las Vegas in August. CrowdStrike released its 2025 Threat Hunting Report on August 4, and VentureBeat’s event coverage followed on August 7. The story was not a single product launch: it was a convergence of two shifts. Attackers were using generative AI to scale identity-based operations, while security vendors were presenting agentic AI for investigation, triage and response. CrowdStrike’s report announcement and VentureBeat’s event coverage document those developments.
The phrase “AI as the next insider threat” needs care. A model does not ordinarily have human intent. The risk is that AI changes who can convincingly obtain trusted access, what a careless or malicious user can do, and how much authority an organization gives automated software.
Free tools Windows power users keep installed
One-click scans. No signup required.
The fake-worker problem: FAMOUS CHOLLIMA
CrowdStrike described FAMOUS CHOLLIMA, a DPRK-nexus adversary, as using generative AI across a campaign to obtain employment and access. It reported that the group had infiltrated more than 320 organizations in the preceding 12 months, a 220% year-over-year increase in organizations infiltrated. CrowdStrike cited AI-assisted résumés and identities, deepfake interview support, and AI coding tools among the reported techniques. These are CrowdStrike’s observations—not an independently audited census of every affected company, nor evidence that every component of each worker’s identity was generated by AI. CrowdStrike’s case description provides its account.
#1 Best Overall
The basic sequence is unsettling precisely because it resembles normal hiring and work:
- Construct a credible profile. AI can help produce résumés, professional communications and supporting material that are consistent in tone and detail.
- Pass screening. CrowdStrike reported deepfake interview support in the campaign. The report does not mean every interview used the same technique.
- Acquire legitimate access. A successful hire or contractor can receive valid accounts, devices and permissions rather than relying on a conventional malware foothold.
- Work within normal systems. AI tools can assist with coding and communication, while access may span repositories, ticketing systems, cloud services or corporate data.
The operation did not depend on AI alone. It also required people, facilitators, devices, remote-access arrangements and weaknesses in organizational processes. The lesson is not to suspect remote employees, contractors or developers who use AI. It is to avoid treating a valid login or an apparently ordinary work pattern as proof that an identity and its activity are trustworthy.
Why identity-based activity can evade malware-focused defenses
Malware detection remains important, but a person using valid credentials may not produce an obvious malware alert. Work can occur through an approved device, VPN, cloud account or SaaS application. Signals may be scattered across HR systems, identity providers, endpoints, code repositories and collaboration tools. Each event can look routine; the pattern across systems may be the warning.
CrowdStrike’s 2025 Global Threat Report said 79% of initial-access attacks it analyzed were malware-free. That is a CrowdStrike finding about its broader threat analysis, not an AI-specific statistic or a universal measure of all attacks. It nevertheless underscores why organizations need identity and behavior telemetry alongside endpoint detection. See CrowdStrike’s report announcement.
Identity governance is the bridge between conventional insider-threat management and AI security. Organizations need to know who or what is acting, what it can reach, whether the activity fits its role, and how to revoke access quickly.
The second risk: agents with access to business systems
A chatbot that only answers a question is different from an agent that retrieves documents, calls APIs, changes records or initiates workflows. Agents may need persistent identities, credentials, connectors and permissions. If an agent can execute code, modify infrastructure, send messages or export data, it is an operational identity—not merely a conversational interface.
That creates a distinct set of failure modes:
- Overprivileged access: an agent has write or administrative access when read-only access would suffice.
- Credential concentration: a service account or token opens several systems, so a single compromise has a wide blast radius.
- Untrusted inputs: an agent treats malicious instructions in a document or webpage as task guidance.
- Weak observability: logs omit the prompt, retrieved content, tool call or resulting change, making an incident hard to reconstruct.
- Automation bias: a human accepts a plausible recommendation without checking its evidence.
- Unsafe action: stale information or a mistaken inference leads to an incorrect remediation or production change.
- Supply-chain exposure: a connector, plug-in, model endpoint or third-party service introduces risk of its own.
CrowdStrike’s 2025 report also described threat actors exploiting tools used to build AI agents, with reported outcomes including unauthorized access, persistence, credential harvesting and malware or ransomware deployment. The risk can lie in a stolen API key, an overprivileged connector or a poisoned retrieval source; it does not require the underlying model itself to be compromised. CrowdStrike’s announcement summarizes the findings.
Recommended Free Tools
How prompt injection works
In indirect prompt injection, an attacker places instructions in content—such as an email, webpage, ticket, document or code repository—that an agent later reads. The content tries to override the agent’s intended task or steer its use of tools. Direct prompt injection happens when an attacker supplies instructions directly to the model. Neither is automatically equivalent to a traditional software exploit: the impact depends on what the agent can access, whether inputs are isolated and validated, and whether actions require approval.
What security vendors showed—and what that does not prove
VentureBeat reported Black Hat demonstrations and announcements involving Microsoft Security Copilot, Palo Alto Networks Cortex XSOAR, SentinelOne Purple AI, Google Cloud security workflows, Cisco’s Foundation-sec-8B-Instruct model and Splunk Mission Control. The capabilities described included investigation assistance, triage, correlation and response workflows. These examples show vendors pursuing AI-enabled security operations; event coverage and product demonstrations are not independent comparative tests. Availability, packaging and permissions can also vary by product edition and change over time. VentureBeat’s coverage attributes the announcements to the vendors and event reporting.
Agentic tools could help teams enrich alerts, correlate data across products, apply consistent investigative steps and reduce repetitive analyst work. But more autonomy can also mean a larger blast radius when an agent is manipulated or wrong. Before treating a vendor’s performance claim as proof, ask whether it came from a demo, a customer case study, a product announcement or independent testing.
Controls to put in place
1. Inventory agents, applications and credentials
Record AI assistants, agents, service accounts, API keys, OAuth applications, model endpoints, plugins, tool connectors, MCP servers and retrieval databases. Note each owner, purpose, data access, permissions, vendor and shutdown method. Include AI features switched on inside software already approved by procurement. An organization cannot govern identities it has not discovered.
2. Apply least privilege
- Use distinct identities for separate agents and workflows; do not share a broad service account.
- Default to read-only access. Grant write permissions only where the workflow genuinely needs them.
- Separate investigation from remediation, and prevent unrestricted shell, database or cloud-administration access.
- Expire credentials, rotate secrets and revoke unused access.
- Limit which tools an agent can call and validate the parameters passed to each tool.
3. Require approval for consequential actions
Put human confirmation in front of actions such as deleting data, disabling accounts, resetting credentials, changing security policy, sending external messages, publishing code, transferring funds, exporting sensitive information or modifying production infrastructure. A reviewer should see the evidence, retrieved context and intended tool call—not only a confident-sounding recommendation. For high-risk systems, deterministic playbooks or read-only assistance may be safer than open-ended autonomy.
4. Log the full chain of activity
Capture the initiating user and agent identity, model and version, task request, relevant retrieved documents, tool calls and parameters, outputs, approvals or overrides, changes made, errors and retries. Protect logs against tampering and retain them under the organization’s incident-response and regulatory requirements. Without this chain, it may be impossible to determine whether a human, an agent or manipulated input caused an action.
5. Monitor behavior across identity, endpoint and SaaS
Watch for unusual OAuth grants, new AI applications connecting to corporate data, agents accessing systems outside their normal workflow, sudden use of unfamiliar tools, unusually large retrievals or exports, and service accounts behaving like interactive users. For workforce identities, investigate mismatches among verified identity, device, location, communication patterns and activity—but avoid treating any single signal as proof of wrongdoing.
6. Make hiring and remote-work verification part of security
HR, recruiting, IT and security should agree on identity and employment verification for sensitive roles, independent reference checks, live technical validation where appropriate, device controls and a clear process for unusual identity concerns. Keep recruiting systems separate from privileged production access, limit contractor permissions, and revoke access promptly at departure. Do not rely on an AI deepfake detector as the sole gate: detection can be wrong, so use layered verification.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →7. Test agents before production
Test against malicious documents and webpages, prompt injection, data exfiltration, tool misuse, cross-tenant access, unsafe code execution, hallucinated actions, connector compromise, denial of service and recovery from a bad tool call. Retest when permissions, connectors, models or retrieval sources change. A safe demonstration environment does not establish safety after an agent receives production data and write access.
Best Value
8. Prepare a shutdown and recovery path
Assign an accountable owner to every production agent. Document and test a kill switch, credential-revocation procedure, means to disable individual tools, rollback for automated changes and a human fallback process. Include agents in incident-response exercises so the team can contain an identity or connector without unnecessarily disabling the whole security platform.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A practical 30-, 60- and 90-day plan
| Timeframe | Priorities |
|---|---|
| First 30 days | Inventory AI tools, agents, connectors and service accounts; identify write and administrator permissions; review data-retention and training terms; review high-risk OAuth applications; add AI-agent compromise and data leakage to incident-response plans. |
| By 60 days | Reduce excessive privileges; centralize agent and tool-call logs; test malicious documents and prompt injection; require approval for destructive actions; align HR, IT and security on verification and offboarding processes. |
| By 90 days | Run an agent-focused security assessment; test shutdown and credential revocation; measure false positives, analyst overrides and automation failures; classify workflows by risk and decide which should remain read-only, deterministic or human-approved. |
The 2026 reality check
Black Hat’s warning was not just about a hypothetical future. In its February 2026 Global Threat Report, CrowdStrike said it observed malicious prompts being injected into generative-AI tools at more than 90 organizations and reported an 89% year-over-year increase in AI-enabled adversary activity. It also reported an average eCrime breakout time of 29 minutes during 2025. These are CrowdStrike telemetry and methodology-specific findings, not an industry-wide census or a claim that AI caused every incident. They do show why organizations should secure AI systems as part of the present attack surface. Read CrowdStrike’s 2026 report release.
The core question is not whether AI is an insider
AI increases risk when organizations combine broad access, weak identity controls, untrusted inputs, poor monitoring and excessive automation. A malicious person can use AI to pursue trusted access; a legitimate user can expose data; and a compromised or manipulated agent can act with permissions its owner failed to constrain. None of those scenarios makes every AI user suspicious, and none makes an incident inevitable.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The defense begins with familiar security engineering: know every identity, grant the minimum access, log actions, verify people and inputs, approve high-impact changes, and practice revocation. Apply those controls to agents as rigorously as to employees and applications—because an agent with credentials and authority can affect the organization whether or not it has intent.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

