Головні звуки українського ІТ. Вгадаєш всі? 👉

Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit

A hacker breached a company's corporate network in less than 10 hours using autonomous AI agents. After completing the attack, the attacker left the victim with an 80-page audit report of their security system.

Leave a comment
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit

A hacker breached a company's corporate network in less than 10 hours using autonomous AI agents. After completing the attack, the attacker left the victim with an 80-page audit report of their security system.

According to analysts at Unit 42 (a cybersecurity division of Palo Alto Networks), during ransom negotiations, the hacker stated that he used advanced artificial intelligence models and special agent frameworks, where separate AI agents were responsible for each stage of penetration, writes Cybernews.

Experts estimate that a typical attack of this scale involving only humans would typically take about two weeks. The use of artificial intelligence has reduced this time to less than 10 hours.

"Instead of using unique zero-day vulnerabilities, the attacker assigned tactical execution to AI agents. They monitored the network status in real time, assessed the situation, acted and adjusted plans," Unit 42 noted.

How AI agents worked

Agents conducted initial reconnaissance and compromised a public API endpoint for initial network access.

While one agent mapped internal microservices, others simultaneously analyzed code repositories, extracting hard-coded tokens and passwords. This allowed access to the secret management system and root-level master passwords.

Individual agents confirmed access to cloud services, identity systems, and CI/CD containers. By hijacking CI/CD processes, the hackers turned the victim company’s own cloud AI services into their own infrastructure, forcing it to pay for the attack’s computing power.

A special "documentation agent" compiled an 80-page security audit detailing dozens of vulnerabilities discovered and exploited.

Unit 42 emphasizes that protecting against automated AI agents requires similar speed of response. Companies are recommended to implement automated protection scripts that can simultaneously revoke credentials, revoke OAuth sessions, freeze CI/CD pipelines, and isolate cloud accounts.

Tokens have become the new prey of hackers: how the Claude account theft scheme works
Tokens have become the new prey of hackers: how the Claude account theft scheme works
On the topic
Tokens have become the new prey of hackers: how the Claude account theft scheme works
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
On the topic
Grok can be fooled with encryption: how hackers force a chatbot to swallow malicious code
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
On the topic
Chinese hacker used DeepSeek via Telegram for autonomous cyberattacks
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.