Just 10% Secure: AI Threat Hunting Tool Unveiled to Combat Shadow AI and Compromised Agents
Cyber Security | 4 min read
A new AI Threat Hunting capability has been unveiled by DivisionHex, an elite cybersecurity practice, designed to uncover hidden AI risks inside enterprise environments — including shadow AI, compromised AI agents, and a newly emerging threat category: agentic insider risk.
As organizations rapidly deploy generative and agentic AI tools across business workflows, security teams are struggling to maintain visibility into how these systems are being used — and misused. A recent survey found that 63% of security teams have a primary mandate to use AI to reduce costs, yet nearly 90% of surveyed organizations have faced an AI-driven incident in the last 18 months.
AI Agents: The New Privileged Insiders
The new capability extends traditional threat hunting methodologies to actively search for signs that AI systems are introducing new attack paths or acting outside their intended permissions.
"AI agents are quickly becoming highly privileged actors inside corporate environments. They can access sensitive data, perform automated tasks, and interact with core systems. If those agents are manipulated, compromised or misconfigured, they don't just behave like a malicious insider – they become one, exfiltrating data or enabling further compromise without anyone realizing it."
— Neil Wyler, VP of Defensive Services
The Overlooked Threat: Trusted AI That Can Be Exploited
While many organizations are familiar with the risks of shadow AI, the industry is overlooking a deeper issue: trusted agentic AI systems that can be influenced or exploited. These systems are vulnerable to several forms of manipulation:
- • Prompt injection attacks — manipulating AI behavior through crafted inputs
- • Data poisoning — corrupting training or operational data
- • Unauthorized credential usage — leveraging AI to access systems it shouldn't
- • Privilege escalation through automation — expanding access via automated workflows
- • External influence altering AI behavior — third-party manipulation of model outputs
In these scenarios, AI systems may unintentionally access sensitive information, perform unauthorized actions, or assist attackers already present in the environment — all without triggering conventional security alerts.
What DivisionHex's Elite Team Investigates
DivisionHex's elite team of hackers conduct deep investigative reviews across enterprise environments to uncover a wide range of AI-related threats:
- • Shadow AI usage introduced by employees without security oversight
- • Unauthorized AI integrations using corporate credentials or sensitive data
- • AI agents accessing data or systems beyond their intended scope
- • Indicators that threat actors are leveraging AI to expand access or persistence
- • Signs that AI models or agents have been manipulated or influenced
The approach provides security teams with both visibility and remediation guidance, helping organizations safely adopt AI without introducing unseen vulnerabilities.
Expert Perspective: Governance Must Keep Pace With Adoption
"AI adoption in the workplace is moving faster than most organizations' ability to monitor and govern it. Without visibility into how employees use generative and agentic AI tools, companies risk creating a new wave of shadow AI and potentially unknown identities. Adoption without governance and monitoring introduces unexpected operational costs. Employing proactive AI threat hunting ensures organizations can harness AI safely while avoiding the downstream risks that come from unmanaged use."
— Christina Richmond, Principal Analyst, Richmond Advisory Group
Key Takeaways
- • Nearly 90% of organizations have experienced an AI-driven security incident in the past 18 months.
- • Agentic AI systems can become insider threats if manipulated, compromised, or misconfigured.
- • The new AI Threat Hunting capability is available as a standalone engagement or as part of broader security assessments.
- • Proactive AI threat hunting is becoming essential for organizations that want to adopt AI safely and responsibly.
