Akamai Report Warns of AI Security Risks: Vibe Hacking and Shadow AI Threats Exposed
August 6, 2026
Akamai’s Enterprise AI Usage Risk Report highlights three attack classes—Vibe Hacking, CursorJacking, and CometJacking—that exploit AI tools, with about half of enterprise AI activity bypassing corporate security and 16.3% of AI browser extensions having known vulnerabilities.
The report also notes a wide visibility gap in security due to shadow AI, where unmanaged tools operate beneath traditional monitoring.
Released as the 2026 Enterprise AI Usage Risk Report, the findings show pervasive decentralization of AI use in enterprises, driven by a small group of power users and a large, unmanaged shadow AI ecosystem increasing security risk.
Context accompanying the release includes insider trading disclosures and historical SOTI references, but the core focus remains on AI security findings and guidance for CISOs.
The findings stress that AI is now a collaborative partner with direct access to sensitive data, calling for governance at the interaction level and real-time analysis of prompts and data flows rather than simple blocking.
Akamai positions its SOTI reports as ongoing insights drawn from its global cybersecurity infrastructure to illuminate trends in cybersecurity and web performance for enterprises.
Now in its 12th year, Akamai’s SOTI reports continue to leverage data from its security backbone to illuminate cybersecurity trends and web performance for global enterprises.
The report includes historical examples of real-world extension attacks and validation from industry players such as LayerX, CISA, Five Eyes, and Gartner on browser security trends.
About 75% of extensions request high or critical permissions, creating substantial risk for data exfiltration via CursorJacking.
Akamai proposes a five-point CISO roadmap: focus on the top 5% of AI power users; eliminate shadow AI via SSO federation and comprehensive discovery; inspect interaction layers with real-time contextual analysis; vet browser and IDE extensions for high permissions and CVEs; and secure autonomous AI agents with least-privilege and behavioral monitoring.
The accompanying five-point checklist urges CISOs to target power users, enforce SSO to curb shadow AI, replace static DLP with contextual inspection, vet extensions, and enforce least-privilege for autonomous agents.
CursorJacking targets browser extensions with high permissions to secretly harvest API keys, code, and conversation history from the browser.
Summary based on 4 sources
Get a daily email with more AI stories
Sources

Investing News Network (INN) • Aug 5, 2026
Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive "Shadow AI" Visibility Gaps
Tech Times • Aug 5, 2026
Akamai Uncovers AI Browser Exploits as CVE Rates Hit 16% in Enterprises
