Executive Summary
Small and mid-size businesses (SMBs) are rapidly adopting AI agents for competitive advantage, deploying multi-agent systems where supervisor agents manage specialist agent swarms. However, this adoption creates significant cybersecurity risks as 40% of SMBs lack AI policies according to ESET's 2026 survey of 4,400 decision-makers. Between March and May 2026, ESET scanned nearly 900,000 AI skills from repositories, finding over 25,000 suspicious and 3,000 malicious skills leading to credential theft and data exfiltration. Attackers are exploiting AI through indirect prompt injection, malicious skills, and supply chain compromises while using AI to enhance traditional attacks like phishing, achieving 54% click-through rates versus 12% for standard attempts.
This incident highlights the emergence of 'shadow AI' risks where employees deploy unsanctioned AI agents with excessive permissions, creating new attack vectors for lateral movement and data exfiltration while traditional threats like ransomware and vulnerability exploitation continue to plague resource-constrained SMBs.
Why This Matters Now
SMBs are deploying AI agents without proper governance as competitive pressure mounts, creating immediate security gaps that attackers are actively exploiting through malicious skills and enhanced social engineering campaigns.
Attack Path Analysis
SMB AI-focused attacks begin with prompt injection or compromised AI skills/tools to gain initial access to business systems. Attackers escalate privileges through AI agent permissions or credential theft from AI-processed data. Lateral movement occurs through AI agent connections to shared drives, email systems, and external services. Command and control is established via manipulated AI outputs or compromised MCP servers. Exfiltration happens through AI agent permissions to external communication or data export. Impact manifests as business disruption, data exposure, or AI-enabled ransomware deployment targeting SMB infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploit indirect prompt injection vulnerabilities in AI agents, compromised AI skills from repositories, or leverage AI-generated phishing campaigns with 54% click-through rates to gain initial access to SMB systems
Related CVEs
CVE-2025-32711
CVSS 7.5The EchoLeak vulnerability in Microsoft 365 Copilot allows data exposure through indirect prompt injection without requiring malicious link interaction.
Affected Products:
Microsoft Microsoft 365 Copilot – < patched version
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Phishing: Spearphishing Link
Command and Scripting Interpreter: JavaScript
Process Injection
Impair Defenses: Disable or Modify Tools
Valid Accounts
Inhibit System Recovery
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Custom Software Security Testing
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.02(g)
DORA – ICT Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Asset Management
Control ID: PI.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001:2022 – Information Security for Use of Cloud Services
Control ID: A.5.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI agent vulnerabilities and prompt injection attacks threaten software development workflows, with malicious skills compromising code repositories and automated systems.
Information Technology/IT
Shadow AI deployment creates compliance gaps across HIPAA, PCI standards while east-west traffic monitoring becomes critical for detecting lateral movement.
Financial Services
Zero trust segmentation failures and egress security weaknesses expose customer data to exfiltration through compromised AI agents and unencrypted communications.
Health Care / Life Sciences
HIPAA compliance violations through unsecured AI tools accessing patient data, with multi-cloud visibility gaps enabling healthcare record breaches and ransomware.
Sources
- The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrivehttps://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/Verified
- ESET SMB Cyber Readiness Index 2026 Global Editionhttps://web-assets.esetstatic.com/wls/en/papers/resources/eset-smb-cyber-readiness-index-2026-global-edition.pdfVerified
- ESET Threat Report H1 2026https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdfVerified
- Microsoft Digital Defense Report 2025https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdfVerified
- OWASP GenAI LLM Top 10 2026https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain AI-focused attacks by segmenting AI agent access paths and restricting lateral movement between business systems. Zero Trust segmentation could reduce the blast radius of compromised AI agents moving through shared drives, email systems, and external services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric could limit the initial reach of compromised AI agents by constraining their network access to only authorized cloud resources and services
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain privilege escalation by limiting AI agent access to microsegmented network zones based on their specific business functions
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely reduce lateral movement scope by inspecting and restricting AI agent communications between internal services and MCP server connections
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility could reduce command and control effectiveness by monitoring AI agent communications patterns across cloud environments and detecting anomalous behavior changes
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by restricting AI agent communications to approved external services and monitoring data export activities for policy violations
While segmentation controls may reduce the scope of AI-powered ransomware deployment, business disruption could still occur within authorized AI agent operational boundaries
Impact at a Glance
Affected Business Functions
- AI-Powered Operations
- Data Processing Services
- Customer Support Systems
- Business Intelligence
Estimated downtime: 3 days
Estimated loss: $75,000
Internal business documents, customer communications, proprietary business intelligence, and corporate data accessible through compromised AI agents with elevated permissions
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit AI agent permissions and prevent lateral movement between business systems through identity-based policy enforcement
- • Deploy Egress Security & Policy Enforcement to control AI agent external communications and prevent unauthorized data exfiltration to third-party services
- • Establish Multicloud Visibility & Control to monitor AI agent activities, detect anomalous interactions, and track suspicious automation across hybrid environments
- • Utilize Cloud Native Security Fabric (CNSF) for real-time inspection of AI agent behaviors, prompt injection detection, and enforcement of distributed security policies
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal AI agent behavior and alert on covert tools, unauthorized access patterns, and malicious skill installations



