Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Securing Your AI Agents: Native AI Detection and Response Across the Full Agentic Path

Enterprises are deploying AI agents at scale, and those agents are taking real business actions. Through LLMs, MCP servers, and APIs, they move money, access patient records, modify code, and send emails. The attack surface has fundamentally shifted, but most security programs are still focused on what an AI says rather than what it does.

When a Security Guardrail Detects the Attack and Still Can't Stop It

Salt Labs recently showed that a single email could hijack the AI agent platform Manus and reach a victim’s connected accounts. The full technical breakdown, with complete evidence, payloads, and screenshots, is in our research team’s write-up, and Dark Reading first reported the finding in an exclusive. This post is the shorter version: what the finding means and what it tells every organization now deploying AI agents. For the full technical detail, read the Salt Labs research blog.

How We Hijacked an AI Agent With a Single Email

Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link.

Salt Claude Connect

Salt Security + Anthropic = a more secure AI ecosystem We’re excited to introduce Salt Claude Connect. This integration will bring continuous MCP server visibility for Claude Enterprise directly into the Salt Security platform. Now you’ll be able to see which organization-managed MCP servers are connected, when they’re added or removed, and their current status (continuously, with no agents, traffic analysis, or manual cataloging required).

Introducing Salt Claude Connect: Continuous MCP Server Visibility for Claude Enterprise

As AI adoption accelerates inside enterprises, security and IT teams are increasingly asking a foundational question: what exactly is connected to our AI, and what can it access? For organizations running Claude Enterprise, Salt now has a direct answer. Salt Claude Connect links Salt to Claude’s Compliance API and provides continuous, read-only visibility into the MCP (Model Context Protocol) servers connected to your Claude Enterprise organization.

AI Security Has a Context Problem

The problem is not a lack of controls. It is connecting them into one attack story. The more time I spend with enterprise AI deployments, the clearer one thing becomes: AI security is incredibly fragmented. There are LLM guardrails, AI gateways, MCP security tools, API security, endpoint controls, SASE, code scanning, and runtime detection. Each solves a real problem, but agentic systems do not experience them as separate layers, and neither do attackers.

The Role of Agentic AI in Cybersecurity

Agentic AI has moved from experimental research to live production environments at unprecedented speed, outpacing nearly every technology security leaders have encountered in recent history. Distinguishing themselves from standard chatbots that merely respond and pause, autonomous agents architect multi-step workflows, interface with tools and APIs, maintain contextual memory, and execute operations with minimal human intervention.

Ten Years, Two Photos, and One Bet That Got Much Bigger

These two photos were taken almost ten years apart. The first is from 2016, with Sam Altman at Y Combinator. The second came from an unexpected encounter in Silicon Valley almost a decade later. I’ll come back to it at the end. With Sam Altman at Y Combinator in 2016. I was 22 when I arrived in Silicon Valley on a one-way ticket, with a little bit of cash that was barely enough for one month of living there, and a thesis I wanted to prove.

Secure What Agents Do, Not Just What They Say

Salt Security and CrowdStrike give joint customers visibility across the full agentic path, from the model to the system where the action lands An employee at a bank asks an AI assistant a routine question. How much money is in my savings account? The assistant answers correctly. The prompt was legitimate. The response was accurate. A model-layer security control inspects both and finds nothing wrong, because nothing is wrong with either. Now look at what happened in between.