AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections tied to credential access and living-off-the-land binaries (LOLBins). Recent analysis from Sophos’ CIXA behavioral engine highlights how these tools blur the line between benign automation and activity typically associated with attackers. The findings are based on Windows endpoint telemetry collected over seven days in June 2026. Detection data show that rules mapped to MITRE ATT&CK tactics such as Credential Access and Execution generated the most alerts. While none of the observed activity was confirmed as malicious, much of it...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!