Menlo Security targets real-time AI agent security with MARS platform
SiliconANGLE Ryan Stevens
Menlo Security has a new tool for watching AI agents in real time. The pitch: stop prompt injection and hide sensitive data before agents blurt it out.
Based on reporting by SiliconANGLE, Ryan Stevens — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AI agents are starting to get the same kind of access that used to be reserved for employees and trusted apps. That is exactly where the trouble begins. Menlo Security says its answer is Menlo Agent Runtime Security, or MARS, a platform meant to watch what agents do as they do it and block risky behavior on the fly.
Ramin Farassat, Menlo Security’s chief product officer, said the core fear is simple: agents can be fooled. They can be tricked by prompt poisoning, and they can also expose data they were never meant to reveal. He made the case at Black Hat USA during a conversation with Krista Case on theCUBE, where the focus was on real-time controls for AI agents and protection against prompt injection attacks.
Farassat was blunt about the limits of the field. He said there will not be a prompt injection system that is 100% safe or complete, and that security teams should treat it as one tool among several. That is a more honest pitch than the usual AI security bravado. It also fits the problem: if an agent is reading poisoned content as if it were normal instructions, no amount of wishful thinking fixes that.
Menlo’s approach is to set policies around what an agent is allowed to do, even when other commands try to push it elsewhere. The platform also scans the data the agent consumes, looks for sensitive information in real time, and can mask that data before it is exposed. In other words, Menlo is aiming less at perfect prevention than at control, visibility, and damage reduction when the model inevitably gets curious in the wrong direction.
My take — AI-written commentary, not fact-checked reporting
This is the right kind of sober security pitch: no magic shield, just controls, masking, and limits. AI agents are being wired into enterprise systems faster than most companies can say “access review,” which is a lovely way to invite trouble. The real test for products like MARS is whether they stay useful once the demo lights go off and the agent starts poking around real data.
Read more about this at: SiliconANGLE