AI-related activity in enterprise SOCs is rising rapidly, but it still makes up only a tiny share of alerts and is overwhelmingly noise rather than real attacks. The main concerns are unsafe AI use, such as permission-bypassed agents, reverse tunnels, keychain dumps, and OAuth grants, while phishing campaigns abuse trusted AI brands like Anthropic, Google Gemini, OpenAI, Claude, and Codex. #Anthropic #GoogleGemini #OpenAI #Claude #Codex #Cursor #ngrok
Keypoints
- AI-related alerts are only 0.43% of SOC volume, but they are growing quickly.
- Most AI-generated alerts are noise, with 94.1% classified as false positives.
- Unsafe AI use includes permission-bypassed agents, reverse tunnels, and keychain exposure.
- Real attacks are rare, but phishing campaigns are abusing AI brand names as lures.
- SOCs should tune legacy detections, hunt for risky AI behavior, and isolate AI tools in restricted environments.
Read More: https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html