Cisco’s Multi-Turn Attack Findings Raise Security Concerns
Cisco recently reported a staggering 6,986 multi-turn attacks against 15 flagship models. Remarkably, attackers who adapted to the ongoing conversation successfully penetrated defenses 88.3% of the time. Amy Chang, head of AI threat intelligence and security research at Cisco, presented these alarming statistics at the Agent Security panel during VB Transform 2026. This statistic should alarm organizations still relying on single-turn red team programs.
According to VentureBeat’s June 2026 Pulse survey of 107 companies, the demand for comprehensive security solutions was evident. Over half (54%) reported experiencing a security incident involving their agents, with 18% acknowledging direct attacks and 36% noting near-misses. Only 32% of companies provide each agent with a unique scoped managed identity, and even fewer (30%) secure their highest-risk agents in isolated environments. Notably, 82% of surveyed enterprises identified provider-native and hyperscaler controls as their primary security layer.
Prominent security vendors echo similar conclusions. Palo Alto Networks recently acquired CyberArk for $25 billion, and CrowdStrike announced a deal to purchase SGNL for $740 million. In a strategic move, Cisco aims to acquire Astrix Security for $400 million, targeting the identity and isolation layers that most organizations have yet to strengthen.
Expert Insights from Amy Chang
Amy Chang, with nearly 20 years of cybersecurity experience, shared her findings with the audience. Her background includes leading global cybersecurity operations at JPMorgan Chase and serving on the House Foreign Affairs Committee. She also teaches at the Middlebury Institute of International Studies. The 88.3% success rate reported by Chang and co-author Nicholas Conley stemmed from their analysis of 30,090 single-turn prompts and 6,986 multi-turn attacks.
Chang emphasized that understanding vulnerabilities in these models is crucial. She described the difference between single-turn tests—a one-time malicious prompt—and multi-turn tests that better represent actual user interactions. The results indicate substantial exposure during extended interactions, often revealing harmful outputs and erratic behavior.
Redefining Agent Security Testing
Cisco is pushing the boundaries of testing methodologies. Chang outlined a proactive framework where agents evaluate deployment scenarios, execute attacks, and assess their success. Despite the complexity of these techniques, Chang reassured, “The answer remains straightforward. I don’t need to be overly creative; I just need to focus on the fundamentals of securing my organization.”
Box’s Perspective on Agent Security
Heather Seylan, CISO at Box, echoed these sentiments, identifying significant gaps in defensive strategies. She pointed out, “Much of what we see in Agent Red Team scenarios uses single-turn tests. This does not reflect real-world AI interactions.” Box utilizes a multi-turn adversary model to simulate more realistic attack scenarios, emphasizing the importance of pressure testing agents to validate execution control.
Seylan recounted how Box’s agents underwent a trust-building process before a single mistake reset that trust. “Monitoring becomes critical, as the models continually evolve, and we can’t predict changes in their interpretations.”
An Innovative Approach at Intuit
Rajesh Parekh, VP of AI and ML at Intuit, shared a builder’s perspective on enhancing agent security. He emphasized a layered approach to monitoring and security. Box’s strategy utilizes concentric layers where permissions are tightly controlled, ensuring agents access only necessary data. Additionally, each task is conducted in a temporary sandbox, limiting any potential blast radius from hijacked agents.
Parekh introduced GenOS (Generative AI Operating System), a central platform that abstracts security, risk, and fraud modeling, maintaining privacy and auditing permissions effectively. This structure allows agents to take on specific tasks without inheriting user privileges.
Continuous Testing as a Necessity
As the focus on security testing evolves, Seylan remarked, “The era of secure code reviews is over. Agents must now enforce security architecture and review their own code for vulnerabilities.” Box is committed to developing a complete agent lifecycle, reinforcing principles of least privilege access. This foundation is vital to maintaining security integrity across the organization.
As vulnerabilities in AI and agent technologies become increasingly apparent, the insights presented at the panel underscore the importance of continuous testing and proactive defense strategies. For the 82% of businesses relying on native controls and the 59% planning to invest in agent security tools in the coming months, adapting to these findings is crucial. Only through thorough, ongoing testing can organizations hope to mitigate the evolving security landscape.
Source: venturebeat.com


