THE APEX TIMES
Salesforce security leaders warn that agentic AI could speed up cyberattacks and defenses at the same time
In a new discussion of “agentic” artificial intelligence, Salesforce executives describe how autonomous systems can complete an intrusion in milliseconds, forcing defenders to add guardrails, human approvals, and governance before AI is allowed to act.
Cybersecurity threats are taking on a new pace and a new risk profile as “agentic” artificial intelligence systems move from assisting humans to running parts of an attack or defense on their own. Salesforce is using a recent example from the security industry to make the point: a ransomware campaign labeled “Jade Puffer,” where an initial human kick-started the operation but an autonomous AI agent carried out the technical steps of the intrusion, including reconnaissance and the encryption and deletion of databases.
Salesforce argues that when the time scale collapses to milliseconds, the usual model of waiting for alerts and then relying on human triage becomes untenable. In that environment, the company’s executives say the practical question is no longer whether to “fight AI with AI,” but how to design defensive agents that do not go rogue. Salesforce compares the dynamic to the “Spy vs. Spy” concept, where both sides act quickly and unpredictably.
Muhammad Fraser-Rahim, Salesforce’s VP of Global Intelligence and Product/Platform Risk, framed the moment as a coming reality rather than a distant concern. While he acknowledged the cinematic feel of autonomous cyber operations, he emphasized that organizations need to ensure they can trust AI systems when those systems are capable of taking technical actions.
The speed advantage is a double-edged sword. Greg Notch, CTO at cybersecurity firm Expel, said agentic AI provides lower-skilled attackers with tools that can look more sophisticated than before, while also letting defenders sift through large numbers of potential-attack indicates to focus on the ones that warrant intervention. Notch added that even when defenders automate parts of an investigation, they typically want humans to review AI work enough to ensure outcomes are correct, with examples including automating actions like resetting identity verification on a compromised laptop.
Salesforce security leadership said the operational challenge is preventing both under-reaction and over-reaction. One risk is that defensive automation responds too aggressively when something looks dangerous but is not. Salesforce cited the example of an autonomous system shutting down an entire hospital data network in response to the compromise of a single, noncritical application, underscoring how quickly collateral damage could occur.
In terms of industry concern, Salesforce referenced survey and research findings that highlight how broadly the category is being treated as dangerous. The company pointed to a Dark Reading readership poll in which 48% of security professionals identified agentic AI and autonomous systems as the most dangerous attack vector, and to an Anthropic report that found “high risk” AI-enabled threats rose to 56% of total cyber incidents, up from 33% a year earlier.
Salesforce’s executives also focused on a core asymmetry: threat actors may only need to succeed once, while defenders must be correct every time. Kelly McCracken, Deputy Chief Information Security Officer and SVP of Security Operations at Salesforce, said “We have to be right every time,” contrasting that with the attacker’s ability to be right only one time. In that context, Salesforce described speed as the hinge factor. Iain Mulholland, Chief Information Security Officer at Salesforce, said the hardest part historically has been fixing vulnerabilities rapidly, reliably, and at scale, and he called the acceleration of remediation enabled by agentic AI models “game-changing.”
To address the speed and accuracy demands, Salesforce says it is designing guardrails that keep humans in the loop for consequential actions. Doug Miller, Salesforce VP of Integrated Threat Management, likened onboarding and trust-building for agents to how people learn to work with a new employee, with the difference that agents do not “sleep.” Salesforce’s security leaders said the practical control is a human approval point for anything that could cause an availability outage. McCracken described it directly: “The button to cause any type of availability outage should be pushed by a human.”
Beyond the cyber layer, Salesforce raised concerns about how AI misjudgments could spill into the physical world, such as building access systems that depend on badges and elevator permissions. Fraser-Rahim described a scenario where an AI agent could incorrectly decide who should have access, potentially locking out authorized staff or allowing someone unauthorized to enter. The company’s message is that enterprises need oversight and alignment across systems that connect cyber authorization to physical infrastructure.
Salesforce also linked these ideas to its broader “Customer Zero” posture, describing it as a set of internal safeguards that mirror what customers can do, what customers can configure, and what can be enhanced through add-ons. The company said this approach helps it test actions and defenses using the same technology it provides externally. Salesforce then described a purpose-built vulnerability agent that continuously triages exposure by scanning to determine whether the company is impacted by specific vulnerabilities, and it also triages and recommends fixes, which it says is how it can compress patch timelines from “seven-plus days” to under an hour. Salesforce added that for Agentforce, governance starts with a Trust Layer that customers can shape by setting which prompts are allowed or blocked, and that controls can identify malicious activity at both the prompt and execution stages.
What Salesforce did not disclose in detail is exactly how much of its defensive workflow is automated end-to-end, what specific thresholds trigger human intervention, or any formal performance metrics such as false-positive rates or time saved across different vulnerability classes. The company also did not publish technical documentation spelling out how agents are sandboxed or how model-specific failures are handled beyond emphasizing human oversight, continuous monitoring, audit trails, and access controls such as least-privilege and strict isolation.
Looking ahead, Salesforce’s executives suggested that organizations should expand the governance conversation beyond security teams to boards and corporate leadership, with questions about funding data compliance and technical controls and about whether monitoring data access is sufficient to understand what people and systems are doing with company data. The immediate watch items, based on Salesforce’s framing, are how enterprises operationalize human approval for high-impact actions, how they manage agent identities and reversibility, and whether vendors can reduce dependencies on any single AI model as the underlying model ecosystem becomes more volatile.
Why It Matters
- Agentic AI changes cyber defense from a largely alert-driven workflow into one where systems can act in milliseconds, raising the cost of mistakes.
- Enterprises may need new governance models for AI agents, including human approvals for high-impact actions and tighter controls on what agents can access and do.
- Security priorities may shift toward remediation acceleration and faster vulnerability triage rather than only detection.
- AI volatility and model-to-model variability could increase the need for infrastructure that works across different foundational models rather than depending on a single provider.
Key Facts
- Salesforce says an example ransomware operation labeled “Jade Puffer” involved an autonomous AI agent completing the technical intrusion steps after an initial human trigger.
- Salesforce executives argue that agentic attacks and defenses are constrained by speed, with intrusions and responses happening too fast for human-only intervention.
- Muhammad Fraser-Rahim said enterprises should focus on trust and guardrails so agents do not go rogue, including limits on AI models with unchecked authority.
- Salesforce said it uses a vulnerability agent to continuously triage exposure and recommend fixes, aiming to reduce remediation time to under an hour versus a longer patch runway in the past.
- Salesforce described an Agentforce Trust Layer that customers can configure to allow or block prompts and to identify malicious activity at prompt and execution stages.
- Salesforce leadership said a human should press the “button” for availability-impacting actions, to avoid damaging overcorrections.
- The company cited a Dark Reading poll and an Anthropic report to support the claim that security professionals and researchers see AI-enabled, autonomous threats as rising.
Technology Related
Amazon is expanding a large automation effort aimed at cutting retail costs, Yahoo Finance reports
A new expansion to Amazon’s automation push, first reported by Yahoo Finance, highlights how the company is trying to improve speed and lower the cost of fulfilling online orders, even as labor and logistics remain major pressures in retail.
BNP Paribas points to infrastructure spending as a potential growth unlock for Meta shares
In a note flagged by Yahoo Finance, BNP Paribas suggested Meta’s next phase of costly infrastructure investment could support another growth engine, even as investors weigh near-term spending and execution risk.
Amazon renews teen mystery series “Sterling Point” for Season 2 on Prime Video
“Sterling Point,” starring Ella Rubin and Jeffery Dean Morgan, was renewed for a second season after launching to a No. 1 global debut on Prime Video.
Alphabet’s Gemma passes one billion downloads as Google spotlights edge and science use cases
In a new post, Google says its open Gemma AI model family has surpassed a billion downloads, pointing to deployments ranging from satellites to health applications and new research built on Gemma-derived systems.
Amazon plans multibillion-dollar robotics manufacturing facility in Austin, aiming to add 300 to 500 jobs
The Seattle-based company is reported to be bringing a major robotics plant to Texas, with hiring plans centered on Austin and an employment range of roughly 300 to 500 roles.
Amazon’s AWS Backlog Climbs to $496 Billion, Renewing Focus on Cloud Demand and AMZN Valuation
A new market report says Amazon’s AWS backlog has reached $496 billion, putting fresh spotlight on the scale and durability of the cloud business that underpins the company’s profitability outlook.
Unrealized stock gains can make earnings look stronger, and Amazon is used as an example
When a company holds shares of other companies, changes in the market value of those holdings can flow into reported results even if the investments are not sold.
Amazon and Alphabet stand out as shoppers move toward AI-driven comparisons
As AI tools increasingly handle product discovery and price comparison, investors are looking at companies with strong commerce, cloud, and advertising reach to capture new demand patterns.
Yahoo Finance argues AMD’s stock surge does not cleanly track the underlying Nvidia picture
A new market commentary points to AMD’s share-price strength versus Nvidia, while warning that the comparison may be misleading when set against how the two companies’ businesses are positioned.
Meta weighs legal and reputational fallout from social media addiction fight, whatever the outcome
A high-profile lawsuit tied to social media addiction places Meta in a difficult position not only if it loses, but also if it wins, according to a new report.