Visa's president of technology Rajat Taneja used Anthropic's Mythos to attack Visa's own payment network at VB Transform 2026. The model chained minor weaknesses into working exploits. Visa open-sourced the harness. That is what it looks like when an enterprise has the engineering depth to act on findings. Most do not. VentureBeat's July Pulse Research wave, drawn from 440 qualified enterprise security respondents across six survey waves since January, found 53% of enterprises have already had an agentic security incident or near-miss.
Three data points from the raw survey cut against how enterprises are telling themselves the story. Enterprises that suffered a confirmed incident or near-miss rated their security tooling 4.39 out of 5. Enterprises that were never hit rated the same tools 4.13. The rescue is doing the marketing. Meanwhile, 57 of 116 July respondents, or 49%, now assign each agent a scoped, managed identity, a 17-point jump from June's 32%. Only 11 of those 57 also isolate those agents. Identity and isolation are being treated as substitutes. They are not. A rogue agent at Meta passed every identity check before exposure. A Fortune 50 agent disclosed by CrowdStrike CEO George Kurtz at RSAC 2026 rewrote its own security policy using valid credentials. Scoped credentials do not bound the blast radius. Sandboxes do.
The enforcement-without-isolation gap has a measurable cost: 53 enterprises enforce runtime permissions but skip isolation, and 31 of those 53, or 58%, have already had an incident, five points above the 53% sample average. Cisco's Amy Chang presented data at Transform showing adaptive multi-turn attackers broke through 15 flagship models up to 88.3% of the time across 6,986 attacks. Single-turn red-teaming missed it entirely. That adaptive attacker lands inside whatever architecture sits behind the guardrails. For 53 enterprises in this dataset, that architecture enforces but does not contain. The full research details how provider lock-in accelerated from 70% in April to 92% in July, why the enterprises closest to real security rate their tools lowest, and what the April-to-July enforcement overshoot means for where agentic security budgets are actually going.
[READ ORIGINAL →]