Skip to content

UPDATED 09:00 EDT / SEPTEMBER 15 2026

SECURITY

Exaforce adds a kill switch for AI agents that go rogue

Agentic security operations startup Exaforce Inc. today launched Exaforce AI Security, capabilities that let security teams see the artificial intelligence agents running across their environments and shut down the ones that turn hostile.

Exaforce built the release around a gap in how enterprise logs record what agents do. Agents act with the identities and permissions of the people who deploy them, so an agent that rotates a key or pushes code leaves an audit trail pointing back at an employee. A reviewer scrolling those logs finds nothing unusual in any single entry. The sequence is what gives an attack away.

Attackers have been working that same gap since at least last year. A June compromise of Canadian competitive intelligence company Klue Labs Inc. exposed its customers’ OAuth tokens, which were then used to pull data from their Salesforce environments. The same technique hit more than 700 organizations through Salesloft Inc.’s Drift chatbot in August 2025. Developers were the target in the Nx “s1ngularity” attack on the npm registry, where their own coding agents, Claude Code and Gemini CLI among them, were turned into credential hunters.

Four capabilities make up the release. Agentless discovery runs continuously and needs nothing installed, turning up connected AI apps, coding agents such as Claude Code and Cursor, hosted agents including custom GPTs, Model Context Protocol servers, skills and development environment plugins.

Each one is tied back to the person and the permissions behind it. A risk layer grades what that turns up and flags excessive permissions or unsanctioned applications. Threat detection and automated response round out the set.

Exaforce matches agent and model provider activity against human identities, endpoint telemetry, file access and code context, looking for misuse and sensitive data exposure that individual log entries would not reveal. Those actions run through endpoint detection and response, identity and model provider admin controls.

The platform can revoke a session, deactivate a model provider key, isolate a device or end an agent’s process, what the company calls an agent kill switch. Security teams set the autonomy on each action, from analyst-approved to fully automatic.

Feeding all of that are endpoint data, productivity suite activity and model provider audit and usage logs, pulled into the knowledge graph Exaforce already builds from identity, cloud, software-as-a-service and code sources. The release extends an integration Exaforce shipped in June with Anthropic PBC’s Claude Compliance API, adding OpenAI Group PBC’s ChatGPT, Google LLC’s Gemini and Microsoft Corp.’s Copilot.

Ankur Singla, co-founder and chief executive of Exaforce, said existing software-as-a-service and endpoint tools were “never built for this era of AI.” Nearly every company is now weighing AI adoption against its risks, he said, and security teams need agent activity landing where their identity, cloud and endpoint data already sit, without another rollout to get it there.

Exaforce AI Security is generally available today on the company’s agentic security operations platform, self-operated or through its managed detection and response service.

HarbourVest Partners, Peak XV Partners, Mayfield Fund, Khosla Ventures and Seligman Ventures backed a $125 million Series B round for the San Francisco-based company in May at a reported $725 million valuation. Exaforce has raised $200 million since it was founded in 2023.

Image: Exaforce

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry