Akamai Report Warns of AI Security Risks: Vibe Hacking and Shadow AI Threats Exposed

August 6, 2026
Akamai Report Warns of AI Security Risks: Vibe Hacking and Shadow AI Threats Exposed
  • Akamai’s Enterprise AI Usage Risk Report highlights three attack classes—Vibe Hacking, CursorJacking, and CometJacking—that exploit AI tools, with about half of enterprise AI activity bypassing corporate security and 16.3% of AI browser extensions having known vulnerabilities.

  • The report also notes a wide visibility gap in security due to shadow AI, where unmanaged tools operate beneath traditional monitoring.

  • Released as the 2026 Enterprise AI Usage Risk Report, the findings show pervasive decentralization of AI use in enterprises, driven by a small group of power users and a large, unmanaged shadow AI ecosystem increasing security risk.

  • Context accompanying the release includes insider trading disclosures and historical SOTI references, but the core focus remains on AI security findings and guidance for CISOs.

  • The findings stress that AI is now a collaborative partner with direct access to sensitive data, calling for governance at the interaction level and real-time analysis of prompts and data flows rather than simple blocking.

  • Akamai positions its SOTI reports as ongoing insights drawn from its global cybersecurity infrastructure to illuminate trends in cybersecurity and web performance for enterprises.

  • Now in its 12th year, Akamai’s SOTI reports continue to leverage data from its security backbone to illuminate cybersecurity trends and web performance for global enterprises.

  • The report includes historical examples of real-world extension attacks and validation from industry players such as LayerX, CISA, Five Eyes, and Gartner on browser security trends.

  • About 75% of extensions request high or critical permissions, creating substantial risk for data exfiltration via CursorJacking.

  • Akamai proposes a five-point CISO roadmap: focus on the top 5% of AI power users; eliminate shadow AI via SSO federation and comprehensive discovery; inspect interaction layers with real-time contextual analysis; vet browser and IDE extensions for high permissions and CVEs; and secure autonomous AI agents with least-privilege and behavioral monitoring.

  • The accompanying five-point checklist urges CISOs to target power users, enforce SSO to curb shadow AI, replace static DLP with contextual inspection, vet extensions, and enforce least-privilege for autonomous agents.

  • CursorJacking targets browser extensions with high permissions to secretly harvest API keys, code, and conversation history from the browser.

Summary based on 4 sources


Get a daily email with more AI stories

More Stories