Cybersecurity

Navigating the agentic AI security era with Wiz

Following Google's $32 billion acquisition of Wiz, security teams must address agentic AI risks like memory poisoning and goal hijacking. With 80% of organizations reporting risky AI agent behaviors, choosing between Wiz, Cisco, and UnderDefense is critical for cloud defense.

Navigating the agentic AI security era with Wiz

The Google acquisition and the Cisco pivot

Google completed its $32 billion acquisition of Wiz on March 11, 2026, after rejecting an earlier $23 billion offer from July 2024. This purchase places the fastest-growing cloud security vendor under Google Cloud. Wiz reached $350 million in annual recurring revenue in February 2024. The company maintains 45% of Fortune 100 customers. Security teams face the challenge of agentic AI, where autonomous systems make decisions and execute tasks without human approval. These agents use APIs to interact with systems and retain context via vector databases. Since 80% of organizations encountered risky behaviors from AI agents, the shift toward agentic security matters. Google’s purchase price includes a 39% premium over the rejected bid. Cisco responded to this shift by acquiring WideField Security in June 2026 to expand Splunk’s Agentic SOC capabilities. Cisco also acquired Astrix Security in May 2026 to secure the credentials that power AI agents. Cisco purchased Galileo Technologies in April 2026 to provide observability for AI. Cisco also acquired DeepFactor in August 2024 to expand its security cloud capabilities. Cisco’s recent pivot involves integrating AI throughout its security stack. The company acquired NeuralFabric in November 2025 to provide an end-to-end generative AI platform for domain-specific Small Language Models. Cisco also acquired EzDubs in November 2025 to improve collaboration features with live voice translation.

Agentic AI threats

Attackers target agentic AI through manipulation and supply chain compromise. Prompt injection via IaC comments or Git messages facilitates tool misuse. Memory poisoning contaminates a vector database, which causes the agent’s context to drift over time. Goal hijacking reframes a task into something unsafe, such as turning "fix the outage" into "disable security controls." Multi-step failure loops occur when each step looks reasonable but the final result is harmful. A single infected image or model automatically deployed from EKS, GKE, or AKS through normal CI/CD processes scales these threats across clusters. Security teams must defend against autonomous agents that learn, adapt, and make decisions that evade human oversight by using valid credentials to perform harmful actions within a network boundary or cloud environment. How can a team manage these invisible risks effectively? You should monitor for shadow AI agents that create invisible risks. Attackers also use server-side request forgery to harvest temporary credentials from cloud instance metadata services. Misuse of cloud CLIs like AWS or Azure allows attackers to bypass established change controls. Unauthorized agents can burn through budgets overnight by triggering runaway autoscaling of expensive servers via adversarial prompts. Wiz research found that AI agents solved 9 out of 10 web hacking challenges. This capability indicates the potency of autonomous systems when they receive offensive objectives. 68% of organizations running self-hosted AI models do so through third-party software, which creates shadow AI agent risks.

Comparing market options

I recommend Wiz for teams needing unified visibility from code to runtime across multicloud environments. Wiz connects code, cloud, and runtime into a single context to prioritize risks. UnderDefense provides a vendor-agnostic platform that runs on top of existing SIEM or XDR investments like Splunk or Microsoft Sentinel. UnderDefense charges $11 to $15 per endpoint each month. However, UnderDefense relies on human analysts to handle the last mile of incident resolution via Slack or Microsoft Teams. UnderDefense maintains 96% MITRE ATT&CK coverage and provides 830% ROI over three years. It also provides 24/7 coverage with a 2-minute alert-to-triage SLA and a 15-minute escalation for critical incidents. CrowdStrike Falcon AI Security detects threats in AI applications at runtime. Palo Alto Networks Prisma AIRS covers agent discovery, risk assessment, and runtime governance. Microsoft Defender for Cloud identifies threats in real time for generative AI applications running within Azure AI services. Check Point AI Agent Security provides inline enforcement across prompts, responses, and agent actions. Wiz provides visibility into AI services and models to help cloud security teams understand AI exposure.

Tool Focus Pricing
Wiz Cloud-native CNAPP Not public
UnderDefense Managed Agentic SOC $11-15 per endpoint/month
CrowdStrike AI application threat detection Per-endpoint
Microsoft Azure AI security Not public