GoFirm
Back to Blog
GoFirm·5 min read

Four Threats Where Attackers Have the Advantage. One Gap Underneath All of Them.

By GoFirm

At the Gartner Security and Risk Management Summit this week, analysts published their 2026-27 ThreatScape: a ranking of critical threats where, in Gartner's words, the attacker holds the advantage. Four threats topped the chart: deepfakes, software supply chain risks, prompt injections, and AI application compromises.

The assessment is sobering. These are not emerging theoretical risks. They are active, accelerating attack vectors where current enterprise defences are outmatched. Gartner issued what amounts to a call to action: organisations need stronger controls, and they need them now.

Reading the analysis carefully, a pattern emerges across all four threats. The gap is not at the perimeter. It is at the execution boundary, where consequential actions are authorised and carried out, and where confirmed human authority is either absent or trivially bypassed.

Deepfakes: 62% of Organisations Already Hit

Gartner reported that 62% of organisations have already experienced some form of deepfake attack, whether through social engineering or attempts to bypass facial and voice recognition systems. Zachary Smith, director analyst at Gartner, noted that even where deepfake detection technologies work today, the AI market is moving fast enough that they may not work tomorrow.

The practical guidance from Gartner was telling. Smith said: "You don't need to detect the deepfake to stop a deepfake attack." A failed authentication check will stop the attacker. The answer is not better deepfake detection. It is a confirmation layer that the deepfake cannot reach.

GoFirm is that layer. A deepfake call to a help desk can reset credentials. It cannot produce a biometric confirmation from a named authority on their registered hardware-bound personal device. The confirmation channel is physically separate from every channel a deepfake can operate through. The attack fails not because the deepfake was detected, but because the execution boundary requires something the deepfake cannot provide.

The M&S and MGM attacks, both covered in this publication, were social engineering attacks that produced credential resets and privilege escalations. Neither required a deepfake. Both would have been stopped by the same control. As deepfakes make social engineering more convincing and harder to detect, the case for moving the control to the execution boundary rather than the communication channel becomes stronger, not weaker.

Prompt Injections: The Execution Chain Is the Target

Gartner cited a 32% increase in indirect prompt injection attacks between November 2025 and February 2026. John Watts, VP analyst at Gartner, described the core risk clearly: "As you get to agentic, autonomous AI, once the execution chain is poisoned, the whole thing goes downhill. You can't really recover from that."

This is precisely the attack surface GoFirm's agentic integration is designed to address. A prompt injection attack works by manipulating an AI agent into believing it has been instructed to take a consequential action. The agent may have been told it has authority. The named human authority never confirmed it.

GoFirm places a confirmation gate at the execution boundary of every high-consequence agentic action. When an agent reaches a sensitive action threshold, it calls the GoFirm confirmation endpoint. The Protocol Engine routes a confirmation request to the named human authority on their registered personal device. The authority confirms with their biometric or the action stops. The agent cannot proceed on a poisoned instruction, because the confirmation must come from a human, on registered hardware, through a channel the agent cannot access or simulate.

Gartner noted that vendors claiming to address prompt injection by scanning for malicious keywords are not solving the problem. GoFirm does not try to detect the injection. It enforces human authority at the point of execution. The injection is irrelevant if the agent cannot execute without a confirmed human decision.

AI Application Compromises: The Attack Surface Is Growing

Gartner recorded 2,130 AI-related CVEs in 2025, a 35% year-over-year increase. Memory poisoning attacks, insecure resources, and poorly secured open source AI frameworks are all expanding the attack surface. Watts noted that widely deployed frameworks are still being found on the internet with admin rights.

The implication is straightforward: as AI applications proliferate, the number of execution paths through which a compromised system can take consequential action is growing rapidly. Each new AI application is a potential new initiation path for an unauthorised action.

GoFirm operates uniformly across all three initiation paths: human-to-human instruction chains, agentic AI workflows, and infrastructure control plane access events. The confirmation primitive is the same regardless of where the action originates. A compromised AI application reaches the same execution gate as a human operator, and it faces the same requirement: confirmed human authority on a registered device before execution proceeds.

Software Supply Chain: Credentials and Secrets at Scale

The supply chain threat identified by Gartner is partly a credentials and secrets problem. Automated worms are sweeping repositories for credentials and secrets. Developers are exposing sensitive data on third-party platforms. CI/CD pipelines are being compromised.

The downstream consequence in each case is the same: an attacker or a compromised automated process obtains the credentials or tokens needed to take consequential action within an organisation's systems. Once those credentials are in hand, the execution boundary has no confirmed authority requirement to stop what follows.

This is the same structural gap as every other category on Gartner's list. The perimeter is bypassed. The credential is valid. The action executes. GoFirm closes the gap at the execution boundary, regardless of how the attacker obtained their access.

The Common Thread

Gartner's four threats are technically distinct. Deepfakes operate at the human social layer. Prompt injections operate at the AI instruction layer. AI application compromises operate at the software vulnerability layer. Supply chain attacks operate at the infrastructure and secrets layer.

What they share is a common destination: execution of a consequential action without confirmed human authority. In each case, the attacker's goal is to make something happen: a credential reset, a data exfiltration, a privilege escalation, a destructive payload. In each case, the route to that goal runs through an execution boundary that has no confirmed authority requirement.

Gartner is calling for stronger controls. The control that addresses all four threats in a single primitive is an execution-layer authority confirmation gate: biometric, out-of-band, deterministic, and permanently recorded. That is GoFirm.

The attacker holds the advantage right up until the execution boundary. GoFirm is where that advantage ends.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Rob Wright, 4 Critical Threats Where Attackers Have the Advantage, Dark Reading, June 4, 2026

2. Gartner Security and Risk Management Summit, ThreatScape 2026-27, presented by John Watts VP Analyst, June 2026

Share this article