AI-Driven Cyberattacks Enter New Phase: Autonomous Fraud and Digital Trust Abuse
Autonomous fraud agents powered by large language models (LLMs) are now conducting end‑to‑end social engineering campaigns that generate convincing deepfake audio/video, harvest credentials, and manipulate trust without human oversight. These agents leverage LLM‑driven dialogue planning, voice‑cloning pipelines (e.g., Tortoise‑TTS + Wav2Lip), and synthetic phishing kits to bypass traditional email and voice‑call defenses. In 2026, global losses from AI‑driven fraud are projected to reach $12 billion (+35% YoY), with vishing success rates rising 22% when deepfake audio is used and attacker analyst workload reduced by up to 60%. Detection requires behavioral analytics, zero‑knowledge identity verification, and continuous model‑based threat hunting.
Outerlimit Secures $16M to Build ZeroTrust Security Layer for Autonomous AI Agents
Outerlimit has secured $16M in pre-seed funding, led by Albion VC, to deploy a zero-trust enforcement layer for autonomous AI agents. The solution targets the agent-action boundary—the critical interface where LLM-based agents invoke external tools and APIs—to prevent unauthorized tool execution, data exfiltration, and model poisoning. By injecting a Policy Enforcement Point (PEP) sidecar using an OPA-compatible Domain Specific Language (OPAAgent) and WebAssembly (WASM) policies, the platform provides continuous, real-time authentication and authorization. The architecture leverages hardware-rooted attestation to bind agent identity and action context to trusted anchors, ensuring rigorous control over agentic workflows.
Perimeter Weaponization and the AI Zero Trust Pivot: F5, Cisco, and Tencent AI-Infra-Guard
Threat actors are currently deploying specialized Linux rootkits on F5 BIG-IP APM devices and exploiting vulnerabilities in Cisco Firepower Management Center (FMC) to establish persistence and enable undetected network interception. Simultaneously, the proliferation of autonomous AI agents is bypassing traditional point-in-time Zero Trust verification, necessitating a transition toward high-velocity continuous authentication. CISA has added five newly exploited CVEs to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate patching for federal and regulated entities. To mitigate AI-specific infrastructure risks, Tencent has released AI-Infra-Guard, an open-source scanning engine designed to detect systemic vulnerabilities within AI-driven environments.