“You’re going to start to see agents getting hacked, not people.” — Dave Gerry, CEO, Bugcrowd
Dave Gerry: agents as the next dominant attack vector
Bugcrowd CEO Dave Gerry told Axios that as AI agents gain autonomy, system access and data, attacks against those agents will increase. “It’s going to become the No. 1 attack vector that we’re going to see,” Gerry said, arguing that organizations have granted agents access to what he called “the crown jewels.” That prediction frames the piece: leaders quoted in the source view agent compromise not as a niche risk but as an emerging, primary vector for adversaries.
Ryan McCurdy: govern actions, not just identities
Ryan McCurdy, VP at Liquibase, warned that agents create “a different kind of insider threat” because they can be both the target and the actor inside an enterprise. McCurdy noted a gap in traditional controls: if a compromised agent has legitimate credentials, “traditional access controls only get you so far.” He urged that organizations must govern what an agent can actually change, arguing that a compromised agent and “a well-behaved agent should face the same policies and controls before their actions reach production.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildKevin Surace: limit permissions and require human approval
Kevin Surace, CEO of TokenCore, used a blunt metaphor—“AI agents are like interns with root access and no fear of HR”—to underline the potential for rapid, machine-speed harm. Surace recommended limiting both permissions and an agent’s “blast radius.” For consequential actions he argued for human approval tied to a trusted device and biometric verification: “Approval from an email or popup or another agent is not acceptable.” His rule: agents may “recommend, prepare, and execute routine work, but only an authenticated human can approve an irreversible or high consequence action.”
Noelle Murata: zero trust for non-human identities
Noelle Murata, Chief Operating Officer at Xcape, Inc., described broadly provisioned agents as “high-value, non-human insider threats.” She said threat actors are shifting from manipulating model inputs to “targeting agent identities,” and that over‑privileged integrations let compromised agents “execute unauthorized API actions, exfiltrate data, or move laterally across connected systems.” Murata recommended applying zero trust to agentic workflows by replacing persistent credentials with “scoped, short-lived tokens,” enforcing least-privilege permissions for tools, and extending continuous identity monitoring to “all non-human entities operating across the Internet.”
Critical takeaways drawn from the experts
- Autonomous AI agents with broad permissions can function as non-human insider threats, enabling lateral movement and unauthorized execution.
- Enterprise security controls must treat agent identities with zero trust rigor, substituting persistent keys with short-lived, scoped tokens.
- Security teams need continuous behavioral monitoring and strict API access boundaries to detect anomalous agent interactions.
What this means for security teams, enterprises, and threat actors
Security teams: Expect a shift in focus from solely managing human credentials to treating agent identities as first-class objects for governance, monitoring and policy enforcement, consistent with McCurdy’s and Murata’s recommendations.
Enterprises and procurement leaders: The speakers warn against broad, persistent tool integrations and over‑privileged agents; TokenCore’s and Xcape’s proposals imply a need to reassess permissions models, require human sign-off for high‑consequence actions, and adopt short‑lived tokens.
Threat actors: The source states adversaries may pivot to “targeting agent identities” rather than only manipulating model inputs, meaning compromised agents could be used to execute authorized actions at machine speed, as Gerry and Surace warned.
Taken together, the comments in the source paint a consistent picture: the convenience of agent autonomy brings a parallel need to redefine controls. Leaders quoted here converge on three concrete responses — governance of agent actions, strict restrictions on permissions and credentials, and continuous monitoring — while warning that failure to do so could elevate agent compromise to a principal attack vector. Will organizations move those recommendations into operational policy before attackers test the prediction that “agents” — rather than people — will be the next exploited insiders?
https://www.securitymagazine.com/articles/102572-could-ai-agents-be-the-next-insider-threat




