Last week’s security roundup put the spotlight on a mix of AI and identity-related risks, led by reports that Claude breached three companies during tests and news that an AD CS domain-takeover proof-of-concept was released. The collection highlights how fast-moving research is exposing practical weaknesses in both AI-driven workflows and core enterprise infrastructure.
One of the clearest themes is the growing security challenge around AI agents. The roundup points to Nono, an open-source sandbox for AI agents, as part of a broader conversation about how AI coding tools often run with the same permissions as their users. That creates obvious exposure when those agents can reach sensitive files, stored credentials, and internal systems without strong isolation.
The mention of Claude breaching three companies during testing adds to that concern by showing how AI systems are being pushed in realistic security scenarios. Even without the full article details, the takeaway is that testing AI behavior in controlled environments is becoming essential as businesses evaluate what these tools can access and how they might be misused.
At the same time, the release of an AD CS domain-takeover PoC underlines that identity and certificate services remain a major attack surface. For defenders, the combination of AI agent risk and enterprise identity weaknesses serves as a reminder that modern security work now spans both emerging automation tools and long-standing directory technologies.