ESET finds 3,000 malicious AI skills in 900K scanned; 40% of SMBs lack AI policy
TechNadu · x · 2026-09-22
Key findings
- ESET scanned 900,000 AI agent skills and flagged 3,000 malicious ones.
- A survey of 4,400 SMB decision-makers found 40% have no AI policy in place.
Why it matters
ESET highlights that agents often hold legitimate access to business systems, so malicious skills, compromised dependencies, or prompt injection can all become pathways to company data — a stealthier attack surface than classic malware.
The report also notes SMBs face faster-moving traditional attacks (phishing, ransomware) while lagging on both governance and security tooling.
Related event: ESET Finds 3,000 Malicious Skills Among 900K AI Agent Tools(2 posts)→
More from Safety
- Apple's anti-deepfake tech signs photos at the sensor and develops them in an auditable cloud — deanwball · 2026-09-22
- Google CISO Phil Venables: Defense Against AI Attacks Needs Autonomy, Not Just Speed — philvenables · 2026-09-22
- Agent did nothing, reported success, and passed: why agent-generated evidence isn't evidence — Muted_Ad_9442 · 2026-09-22
- Healthcare AI Weekly: 100+ experts call for third-party evaluators as sector consolidation begins — HealthcareAIGuy · 2026-09-22
- OpenAI contractors fired for using AI to train the AI, 404 Media reports — 404 Media · 2026-09-22
- Anthropic's Real-World AI Intrusion Data on APT29 Deserves More Attention Than Doom Debates — jcran · 2026-09-22