Realtime AI News
Exaforce ships an AI security product with a kill switch for rogue agents
Agentic security operations company Exaforce launched Exaforce AI Security, giving security teams visibility into the AI agents running in their environments and the ability to shut down the ones that turn hostile. The release extends a June integration with Anthropic's Claude Compliance API to OpenAI's ChatGPT, Google's Gemini and Microsoft's Copilot.

Exaforce, a startup selling agentic security operations, launched Exaforce AI Security on September 15, 2026 — a set of capabilities that let security teams see the artificial intelligence agents running across their environments and shut down the ones that turn hostile.
The release is built around a gap in the way enterprise logs record agent activity. Agents act with the identities and permissions of the people who deploy them, so an agent that rotates a key or pushes code leaves an audit trail pointing back at an employee. No single log entry looks unusual; it is the sequence that gives an attack away.
Attackers have been working that same gap since at least last year. A June 2026 compromise of Canadian competitive intelligence firm Klue Labs exposed customers' OAuth tokens, which were then used to pull data from their Salesforce environments. The same technique reached more than 700 organizations through Salesloft's Drift chatbot in August 2025, and in the Nx “s1ngularity” attack on the npm registry, developers' own coding agents — Claude Code and Gemini CLI among them — were turned into credential hunters.
Four capabilities make up the release. Agentless discovery runs continuously and needs nothing installed, surfacing connected AI apps, coding agents such as Claude Code and Cursor, hosted agents including custom GPTs, Model Context Protocol servers, skills and development environment plugins, each tied back to the person and permissions behind it. A risk layer grades what that turns up and flags excessive permissions or unsanctioned applications, while threat detection and automated response complete the set.
Response actions run through endpoint detection and response, identity systems and model provider admin controls. The platform can revoke a session, deactivate a model provider key, isolate a device or end an agent's process — what the company calls an agent kill switch. Security teams set the autonomy on each action, from analyst-approved to fully automatic.
Feeding that are endpoint telemetry, productivity suite activity and model provider audit and usage logs, pulled into the knowledge graph Exaforce already builds from identity, cloud, software-as-a-service and code sources. The launch extends a June integration with Anthropic's Claude Compliance API to OpenAI's ChatGPT, Google's Gemini and Microsoft's Copilot.
"Existing software-as-a-service and endpoint tools were never built for this era of AI," said co-founder and chief executive Ankur Singla, adding that nearly every company is now weighing AI adoption against its risks. Exaforce AI Security is generally available today on the company's agentic security operations platform, self-operated or through its managed detection and response service. The San Francisco-based company raised a $125 million Series B in May 2026 at a reported $725 million valuation and has raised $200 million since it was founded in 2023.
Why it matters
Agents inherit human identities and permissions, so conventional logging cannot express their intent — which makes discovery plus shutdown a precondition for widening agent access. Audit-after-the-fact gives way to live behavioural correlation and human-supervised automated response.
Nearby Updates
All09/16, 04:40
OpenAI backs a House measure that would require independent audits of AI models
OpenAI has come out in support of a bipartisan House proposal that would require independent audits of AI models, according to CBS News. The endorsement puts a leading lab behind external third-party safety assessments at a moment when the industry's stance on verifiable oversight is shifting.
09/16, 04:12
Meta lets AI coding agents handle WhatsApp Business setup through a new MCP server
Meta introduced a WhatsApp Business Tools MCP server that connects AI coding agents such as Claude, Cursor, Codex and ChatGPT directly to the WhatsApp Business Platform. The server lets an agent create accounts, verify phone numbers, register Cloud API access, build message templates and monitor checks that previously required jumping between Meta's developer tools.
09/16, 04:47
Spain's data watchdog publicises its first AI agent-linked data breach report
Spain's data protection watchdog has publicised the country's first data breach report tied to an AI agent, saying it received the first notification of a personal data breach allegedly carried out by an artificial intelligence agent. The case pushes autonomous agent behaviour into the regulatory frame, raising immediate questions about attribution, logging and oversight.
09/16, 04:04
VoiceAIWrapper adds a guided AI agent builder to its white-label voice agent platform
VoiceAIWrapper, a white-label AI voice agent platform aimed at agencies, has added a guided AI agent builder, per a press release carried by PRLog. The update shifts voice agent configuration away from custom development and toward a step-by-step setup that agencies can resell.