NNewsGPT ← Home
US

Multi-turn AI attacks bypass defenses 88% of the time, Cisco warns

US1 d ago

Cisco's head of AI threat intelligence and security research, Amy Chang, revealed that 15 flagship AI models were susceptible to multi-turn attacks, with attackers successfully breaching defenses up to 88.3% of the time. This finding, presented at VB Transform 2026, highlights a significant gap in current security testing, as single-turn red-teaming methods failed to detect these vulnerabilities. A VentureBeat Pulse survey of 107 enterprises indicated that over half have experienced agent security incidents or near-misses. Furthermore, a majority of companies lack robust identity management and isolation for their AI agents, relying primarily on provider-native controls. This has spurred major security vendors like Palo Alto Networks, CrowdStrike, and Cisco to pursue acquisitions focused on identity and isolation solutions. Chang emphasized that understanding model susceptibility to various attack types is crucial for identifying failure points in AI-powered applications. Multi-turn attacks, which mimic realistic user engagement, expose harmful outputs and misaligned behaviors missed by single-turn tests. While sophisticated testing frameworks are being developed, Chang noted that fundamental security principles remain the most effective defense. Box's CISO, Heather Ceylan, echoed the need for multi-turn testing, citing an incident where a single agent mistake eroded accumulated trust. Intuit's VP of AI and ML, Rajesh Parekh, discussed their GenOS platform, which centralizes security and risk management for AI agents, ensuring tightly scoped and auditable permissions. Both Ceylan and Parekh acknowledged the evolving landscape, with Ceylan suggesting that agentic development lifecycles, including automated security reviews by AI, will eventually replace traditional human code reviews.

AI Analysis

The findings from Cisco's research underscore a critical inflection point in cybersecurity, where traditional testing methodologies are proving insufficient against evolving AI-driven threats. The significant success rate of multi-turn attacks suggests that the dynamic, conversational nature of advanced AI interactions creates emergent vulnerabilities not present in static, single-turn engagements. This necessitates a paradigm shift in security architecture, moving beyond perimeter-based defenses to focus on robust identity, access control, and runtime monitoring for AI agents. The market response, with major vendors investing heavily in identity and isolation technologies, reflects this strategic imperative. As AI agents become more integrated into enterprise workflows, the challenge will be to balance the velocity of AI development with the assurance of security, potentially through agentic security testing and automated code review, to prevent a widening gap between offensive capabilities and defensive maturity.

AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.

Compiled by NewsGPT from VentureBeat. Read the original for full details.