Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

Detection · LONDON

AI Tool Adoption Floods SOCs With Alert Noise, Not Agent Takeovers

By Ava Okello, Detection, London

LONDON - Enterprise adoption of coding agents and consumer AI assistants is generating a fast-growing class of security alerts that are overwhelmingly benign, according to a September 2026 analysis of SOC telemetry published by Intezer researchers and summarized by The Hacker News and the Cloud Security Alliance.

The researchers reviewed roughly 16.9 million SOC alerts across enterprise environments and identified about 73,000 AI-related alerts, or 0.43 percent of total volume. That AI-related share grew 685 percent between February and June 2026. Of the AI-related alerts examined, 94.1 percent were classified as noise from legitimate tool use, 5.8 percent as genuine policy or exposure risk, and 0.02 percent as confirmed attacks.

None of the confirmed attacks in the dataset involved an organization's own AI agents being compromised or acting maliciously. The confirmed cases instead involved phishing and social engineering that used AI brand names as lures. The larger operational cost is noise: detections written before AI agents existed now fire at high severity on routine developer-agent activity such as installers, package installs, local port checks, and multi-step automation. Across the noisiest AI-related detections in the study, the benign share ranged from 77 percent to 99 percent. Automated triage suppressed 81.7 percent of AI-related alerts without analyst review, and only 5.4 percent were escalated to a human.

For detection engineering teams, the practical response is not a blanket new rule pack for AI attacks. It is tuning the highest-volume legacy detections that fire on sanctioned agent behavior, establishing baselines for approved tools, and hunting separately for permission-bypass flags, unauthorized reverse tunnels such as ngrok, and unusually broad OAuth grants. Isolating agents in constrained environments can also make agent activity easier to attribute than user activity. The Cloud Security Alliance research note on the same dataset frames today's 0.43 percent share as a floor rather than a ceiling, and warns that teams sizing AI-alert handling to current volume may be under-provisioned within a quarter.

Ava Okello covers detection engineering and alert operations for SOCtember from London.

Back to Detection