AI agents breached enterprise network and deployed ransomware within hours

← Back to the feed

AI agents breached enterprise network and deployed ransomware within hours

The Register · 6 hours ago

A ransomware attacker used frontier AI models and agentic frameworks to breach an enterprise network in under 10 hours, a task security firm Unit 42 says would typically take human operators around two weeks. Rather than exploiting a novel zero-day or displaying elite hacking skill, the attacker delegated nearly every stage of the intrusion to AI agents that monitored, evaluated and re-planned in real time, sharply increasing the speed of the attack chain. The case highlights growing concern that AI-assisted operations are lowering the skill and time barriers to sophisticated cyber attacks.

The AI agents carried out reconnaissance, breached a public API endpoint to tunnel into the network, mapped internal microservices, and scraped code repositories for hard-coded tokens and passwords. Using stolen credentials, the agents accessed the victim's secret-management system, seized master administrative credentials for root access, then hijacked CI/CD workflows to steal cloud keys and repurpose the victim's own cloud AI services as attack infrastructure. After completing its objectives, the system left the victim an 80-page report detailing dozens of exploited security failings; Unit 42's parent company, Palo Alto Networks, argues defenders must now deploy their own AI agents and treat AI systems as core infrastructure requiring strict inventory and access controls.

  • AI agents ran an entire ransomware attack in under 10 hours
  • Attack normally takes human operators roughly two weeks
  • Agents even left victim an 80-page security failings report

AI Cybersecurity Technology

Read the full article at the source →

Originally published by The Register as “AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit”.