Fighting fire with fire is a known response. Fighting AI attacks with AI defense is a growing practice. But instant remediation is new and welcome.
Sevii has extended its Autonomous Defense & Remediation (ADR) platform with a new AI security module. As the speed and scope of AI driven attacks increases, it requires an AI defense. Since companies are rarely aware of all the shadow AI used within the organization, this defense needs to operate at runtime irrespective of source, with effectively immediate and autonomous remediation.
This is what the new module provides. As with Sevii’s wider ADR platform, alerts are received from the customer’s entire security detection stack. The new module ingests these alerts in real-time and then analyzes them. While existing tools can detect attacks, they tend to report them to the SOC. Sevii’s new AI module ‘intercepts’ this reporting and responds instantly and autonomously with its own AI-driven machine speed.
It uses AI agents (it calls them ‘cyber warriors’) to undertake a seven-day retrospective context hunt to determine whether the detected action is normal or abnormal. This is used to confirm a genuine AI attack. If genuine, the cyber warriors look for the possibility of the same attack occurring elsewhere within the customer’s infrastructure. This identifies whether the attack is broader than the initial detection and helps to determine if it requires immediate remediation.
“When we get the AIDR detection, we start the action to determine whether it is good or bad from policy, or is it acting in the fairest way,” explained Sevii’s CEO and co-founder, Curt Aubley. “We immediately collect all the data we need. We call it a hunt. We grab all that data and analyze it to be able reverse engineer the attack and take any necessary action.”
If remediation is necessary, it may be autonomous or triggered by a human defender in the loop. Being realistic, the ‘human in the loop’ option is a marketing comforter: companies like to have that option even if it is counterproductive. In reality, any defense against an AI attack must be able to react with the same machine speed as the attack itself. Requiring a human in the loop defeats this.
“Having a human in the loop may be required by today’s governance policy. But consider the damage and speed at which OpenAI rogue agents attacked Hugging Face,” commented Aubley. “Seventeen seven-minute actions. It’s mathematically impossible for a human to keep up with that.” The speed and process of remediation is essential to the success of any defense against an AI-driven attack.
Sevii’s remediation can be immediate. While it is gathering context for its steps, it may detect a high volume of data leaving the customer. It performs an instant intelligence . Is this a standard occurrence? Where is the data going? Is it going to a known command and control C2, or infrastructure that is known to be bad? Knowledge that a destination may be bad could have occurred within the last 15 minutes, but Sevii already knows it.
If the customer is sending data to a dangerous location, “We will absolutely immediately stop that activity and autonomously do an impact analysis as well to see what data left and how quickly we stopped it,” said Aubley
A simple example of Sevii’s standard remediation process can be seen in the autonomous action it takes against a compromised laptop. “Let’s say an employee is using a laptop and uses the same identity and password to access different systems such as SAP, Salesforce or ServiceNow,” explained Aubley. “Whatever the applications are, we may get a detection that the laptop has been compromised, and the user’s identity is starting to do weird activity – it may be logging in to systems it’s never logged into before. So, we’ll do our hunt and validation to confirm the detection is a true positive.”
The step is isolation. “We will isolate the laptop and disable the account, remove those sessions from that account, and force the person to reset their password. So, first the identity portion is stopped, so the adversary can no longer log into these other systems. That stops the spread. We securely connect to the laptop and remove the bad processes and registries and things of that nature,” he continued.
“Once done, we remove the isolation. We do a final validation, and we watch that system to make sure that it is not acting strangely anymore. If satisfied, we release it back to the customer.”
This complete AI-driven autonomous process typically takes between two and fifteen minutes. Downtime is minimal. Since an AI attack typically takes between 30 seconds and 30 minutes, with an average of the same 15 minutes that it will take Sevii to remediate, this new AIDR module can truly be described as a successful attempt at fighting fire with fire.
Related : UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
Related : Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
Related : Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable
Related : Can We Trust AI? No – But Eventually We Must
Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.
More from Kevin Townsend
Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
Coast Guard Establishes Office of Maritime Cybersecurity Policy
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Hackers Start Exploiting Critical Langflow Vulnerability
Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Ransomware Gang Claims Nutex Health Data Breach
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
9.5 Million Impacted by Aesto Health Data Breach
WatchGuard Patches Critical Vulnerabilities
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
