Vetric and Cobalt warn generative AI insider threats target video platforms
Cybersecurity executives from Vetric, Gravwell, CYGNVS, and Cobalt warn that generative AI and autonomous agents are increasing insider threat risks for organizations. The experts highlight the need for improved verification processes, out-of-band response playbooks, and adversarial testing to mitigate risks from executive impersonation and over-privileged AI agents.
Key Takeaways
- Vetric VP Amit Shuster reports attackers are combining public video with organizational knowledge to create convincing CEO deepfakes for fraudulent fund transfers.
- CYGNVS CEO Arvind Parthasarathi recommends out-of-band command centers to manage incidents where primary communication systems are compromised by autonomous agents.
- Cobalt CTO Gunter Ollmann advocates for adversarial testing to determine the 'blast radius' of over-privileged AI agents acting as non-human insiders.
- Gravwell VP Mike Wade emphasizes that detecting insider activity requires full-fidelity telemetry across identity, cloud, and network logs to identify slow-moving patterns.
Why It Matters
The rise of synthetic media and autonomous agents shifts the security perimeter from external firewalls to internal identity verification. For streaming organizations, this means deepfake video is no longer just a content moderation issue but a direct threat to financial and operational integrity. As companies grant AI agents broader transactional authority, the risk of machine-speed data exfiltration increases without traditional malicious intent. The industry must now pivot toward zero-trust architectures that treat every internal video interaction and automated agent as a potential vulnerability. Watch for the adoption of autonomous pentesting tools specifically designed to stress-test the permissions of non-human identities within corporate media workflows.
Additional Context
The broader agentic AI security landscape is evolving rapidly as vendors and operators grapple with autonomous systems that hold elevated credentials. In June 2026, Ericsson launched its AI in RAN commercial software subscription claiming up to 20% higher downlink throughput across more than 15 live deployments, while Verizon disclosed that its 60,000-site vRAN is now applying agentic AI to planned configuration changes and service assurance. Verizon publicly called for industry-wide interoperability standards for agentic systems, highlighting a critical gap: no standardized protocol yet exists for agentic command, control, and assurance across multi-vendor networks. This mirrors the insider threat challenge described by Vetric and Cobalt executives, where autonomous agents with broad permissions create attack surfaces that traditional security models were never designed to address.
Nokia has moved aggressively to position its agentic AI stack as a full-stack automation platform, announcing partnerships that extend well beyond the radio access network. At DTW Ignite in June 2026, Nokia announced work with AWS and Databricks to build the data, cloud, and control layers for autonomous networks, introducing vendor-neutral data transformation logic to reduce platform lock-in. Nokia claims its autonomous networks portfolio is already delivering automation rates higher than 90 percent, service delivery times of four hours or less, and up to 85 percent reduction in slice rollout time. These figures underscore the scale at which agentic systems are being granted operational authority, precisely the scenario that CYGNVS and Gravwell security leaders flag as dangerous when verification processes lag behind deployment speed.
The competitive divergence between Ericsson and Nokia on AI architecture has direct implications for how insider threat models must adapt. Ericsson and Nokia are diverging like never before on AI-RAN strategy, with Nokia building its entire Layer 1 RAN on Nvidia's CUDA platform and GPUs following the chipmaker's $1 billion investment, while Ericsson pursues a cloud-first agentic blueprint running on Amazon Bedrock. Ericsson's agentic service experience layer spans customer journeys, revenue management, and network operations, creating closed loops where experience metrics influence service changes and optimization decisions. For security teams at video platforms and streaming operators, this proliferation of agentic systems with cross-domain access means that the insider threat surface now includes non-human identities operating at machine speed across OSS, BSS, and content delivery layers simultaneously.
Read full article at securitybrief.co.uk
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source