HardenStance’s RSAC 2025 briefing shows that AI was again the dominant theme, with vendors focusing on securing generative AI use by employees and embedding agentic AI into security operations. The report highlights major product launches and research from Akamai, Cisco, CrowdStrike, Google, Palo Alto Networks, Qualys, and Sandbox AQ as the industry shifts from AI experimentation to practical controls, detection, and autonomous defense. #RSAC2025 #Akamai #Cisco #CrowdStrike #Google #PaloAltoNetworks #Qualys #SandboxAQ #Unit42 #PrismaAIRS #CharlotteAI #TotalAI #AQtiveGuard
Keypoints
- Annual cybersecurity reports like this one typically begin with an executive summary or theme overview, followed by sections on major threats, notable vendor announcements, technical research findings, and strategic recommendations for defenders.
- They often conclude with a forward-looking assessment of emerging risks, market direction, and practical mitigation priorities for enterprises, security teams, and technology providers.
- In this report, the dominant theme is AI security, especially protecting organizations from risks introduced by generative AI applications and preparing security operations for agentic AI.
- A recurring takeaway is that AI risk is no longer limited to model behavior; it now includes employee misuse, developer exposure, insecure integrations, adversarial inputs, and shadow use of AI tools.
- Akamai introduced a “Firewall for AI” to block unauthorized queries, adversarial prompts, and large-scale data scraping against AI applications, LLMs, and AI-driven APIs.
- Cisco made AI Defense generally available, emphasizing protection against misuse of AI apps and reporting malware embedded in popular Gen AI applications relied on by customers.
- CrowdStrike launched Charlotte AI Agentic Response and Agentic Workflows, moving toward AI that can automatically investigate incidents, identify lateral movement, and support playbook execution.
- Google announced multiple AI agents across Google Unified Security, including tools for detection engineering, response automation, alert triage, and malware analysis.
- Palo Alto Networks unveiled Prisma AIRS to secure enterprise AI ecosystems, with capabilities such as model scanning, posture management, red teaming, runtime security, and AI agent protection.
- Palo Alto Networks also expanded Prisma Access Browser to control use of more than 2,000 Gen AI apps, showing how browser-based controls are becoming important as encryption limits network visibility.
- Cortex XSIAM 3.0 added Gen AI-driven email analysis to detect phishing intent, using language inference to score emails based on urgency, financial pressure, and other cues.
- Unit 42 published research showing nine AI-agent attack scenarios that can lead to information leakage, credential theft, tool exploitation, and remote code execution.
- The Unit 42 research stresses that many AI-agent weaknesses are framework-agnostic and often stem from insecure design patterns, misconfigurations, and unsafe tool integrations rather than the frameworks themselves.
- Qualys expanded Total AI to test on-premises LLMs, detect more than 38 jailbreak and prompt manipulation scenarios, and identify “hallucination attacks” that trick models into suggesting malicious third-party packages.
- Qualys also highlighted multimodal threat detection, including prompts hidden in images, audio, and video, and endpoint scanning for OpenAI-compatible chat-completion APIs across major cloud and self-hosted environments.
- Sandbox AQ expanded AQtive Guard beyond cryptography management into broader identity and AI SecOps use cases, including monitoring of human and non-human identities and automated remediation.
- Overall, the report reflects a broader industry shift from securing traditional infrastructure to securing AI itself, including models, agents, browsers, APIs, identities, and security workflows.
- The most significant trend is the rise of proactive AI defense: vendors are not just warning about AI risk, but embedding AI into security platforms to automate analysis, response, and policy enforcement.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)