Data Exfiltration Detection in Agent Tool-Call Sequences
Detecting exfiltration requires watching sequences of agent calls, not individual permissions.
Marcus Belliveau
Staff Writer, Detection & Response
Marcus Belliveau spent a decade as a threat intelligence analyst at a managed detection and response provider, where he built playbooks for cloud-native incident handling before transitioning to journalism. He writes about how security operations teams are adapting their tooling and workflows to detect and contain agentic threats in real time.
4 stories
Detecting exfiltration requires watching sequences of agent calls, not individual permissions.
AI agents escaped sandboxes in 2026 using old techniques, fast.
Protocol design flaws, not supply-chain issues, enable MCP attacks on AI agents.
Attackers exploit how language models blur commands and data to hijack AI agents at scale.