Groowe Groowe BETA / Newsroom
⏱ News is delayed by 15 minutes. Sign in for real-time access. Sign in

Mondoo Expands Vulnerability Management to Shadow AI

globenewswire.com

Mondoo Expands Vulnerability Management to Shadow AI SAN FRANCISCO, July 29, 2026 (GLOBE NEWSWIRE) -- Mondoo, the Agentic Managed Vulnerability Service and advanced continuous threat exposure management (CTEM) platform, today announced a major expansion of its platform: comprehensive discovery, risk assessment, policy control, and remediation for enterprise AI agents. With new tooling for managing fast-growing AI fleets, Mondoo gives security teams the visibility and controls to define which AI tooling is allowed on company endpoints — surfacing unsanctioned AI usage, enforcing policy, and eliminating risky use cases before they do damage.

"AI risk used to be centered in the cloud — model endpoints, APIs, and data pipelines. Today it sits on the employee workstation," said Dominik Richter, Co-Founder of Mondoo. "Agents on laptops execute commands, hold credentials, and reach directly into internal systems, and most security teams can't even see them. Mondoo gives customers the ability to discover all AI usage, identify risk, and remediate using tools they already know and love."

While existing tools monitor agentic activity at runtime and flag issues as they happen, Mondoo's approach is preventive control — governing AI tooling and its capabilities before they can be misused. Malicious skills never run, banned agents don't operate, and unapproved models never touch company data.

Mondoo released AI Skill Check, its AI skill intelligence tool, earlier this year. The intelligence gathered since launch makes the findings clear: shadow AI is out of control. Shadow IT isn't new — employees have always added tools the enterprise didn't greenlight. But those tools never acted on their own. Employees are now adopting autonomous AI tools en masse — coding agents, IDE assistants, browser extensions, and third-party skills — many of which connect directly to internal systems through Model Context Protocol (MCP) servers and chain actions across applications. Much of this adoption is unsanctioned, and most of it is completely invisible to the teams tasked with securing it.

The Endpoint Is the New AI Control Plane

The employee workstation has become the hub for managing this risk. AI agents execute shell commands, access credentials, modify source code, and interact with cloud services and other applications — and all of these workflows emanate from the company endpoint, making it the operational control plane for enterprise agentic adoption. Yet most organizations remain blind to agentic activity across their fleet: which tools employees are running, what capabilities they've provisioned, and what risk that represents.

Mondoo discovers every AI agent, skill, MCP server, and model within the enterprise fleet, assesses risk, and drives remediation through tools already in use:

Mondoo is a silver sponsor of the OWASP GenAI Security Project, the community-driven initiative developing open source guidance and standards for securing generative and agentic AI.

The new AI security capabilities are available now. For more information, visit mondoo.com, schedule a demo, or visit Mondoo at Black Hat USA 2026, Booth 5100 in the AI Zone.

About Mondoo

Mondoo's Agentic Managed Vulnerability Service, a combination of local expert security professionals and a proven AI-native platform, delivers the outcomes security professionals need, helping them transition out of the endless cycle of scanning and reporting and into actual remediation. The Mondoo platform is also available standalone for teams that run vulnerability management themselves. Trusted by more than 300 customers worldwide, including Fortune 50 companies, Mondoo prioritizes risks by business impact and exploitability, collects structured, context-aware data from the entire IT infrastructure and your AI tooling, and provides actionable remediation guidance, including automation code and ready-to-approve pull requests, that eliminates vulnerabilities rather than just categorizing them. Mondoo's customers have reduced vulnerabilities by 60%, achieved mean time to remediation under 16 days, and accelerated remediation by 10x compared to manual approaches. With seamless ITSM integrations, transparent security pipelines, and guaranteed outcomes, Mondoo bridges the gap between security and engineering to fix what matters most to the business.

Media Contact

Elle Mullen

Marketbridge for Mondoo

Mondoo@marketbridge.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/a0f3a63c-ab34-4a50-ac91-f822fb7172f2