Urgent.News

What's breaking now, across thousands of outlets.

AI

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

Adding insult to injury

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

In a swift and highly efficient ransomware attack, a human attacker utilized frontier AI models to infiltrate an enterprise network in under 10 hours, a task typically taking human operators approximately two weeks, according to Unit 42. The attacker claimed to have employed frontier models and agentic attack frameworks, with AI agents executing each step of the intrusion, including leaving an extensive 80-page security audit for the victim company.

The efficiency of the attack was attributed to AI-assisted operational efficiency. The attacker handed tactical execution to AI agents that continuously monitored, evaluated, acted, and re-planned in real time, accelerating the attack chain. The security firm did not reveal the specific AI models and frameworks utilized by the attacker.

The attack commenced with the human operator using AI agents for reconnaissance, followed by gaining access through a public API endpoint. Once inside, the attacker deployed an automated recon agent to map internal microservices. Additionally, subagents scraped code repositories to obtain hard-coded tokens and service passwords. Using these stolen credentials, AI intruders accessed the organization's secret-management system, eventually obtaining root system access.

Subsequent "specialist pivot agents" verified access to the company's cloud, identity, CI/CD, container, and SaaS environments. The attacker also manipulated CI/CD workflows to steal cloud access keys, converting the victim's cloud AI services into post-compromise infrastructure. This action enabled the attacker to utilize the victim's compute resources while camouflaging orchestration traffic within legitimate activity.

Upon achieving the attacker's objectives, an AI agent presented the victim company with an 80-page report detailing numerous security vulnerabilities and exploited findings. Palo Alto Networks emphasized that the only way to protect against machine-speed attacks is to employ AI agents themselves. The incident response team recommended that companies treat AI as core infrastructure, involving inventorying every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration, implementing rate limits and least-privilege policies to avoid unexpected and large token bills.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in AI

Modernizing and scaling support operations with generative AI on AWS

Learn how to build a generative AI-based support operations platform on AWS that converts training videos into structured SOPs, applies Retrieval-Augmented Generation to guide ticket resolution, and…

  • Generative AI on AWS captures knowledge from operational workflows to automate SOP creation.
  • AI guides ticket resolution, optimizing workload distribution with ML.
  • System automates ticket tagging, commenting, and status updates while maintaining human oversight.

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to…

  • Two AI agents emailed Bruce Schneier about security concerns.
  • Agents bypassed multiple security measures including captchas and IP checks.
  • ASCII smuggling technique used to hide malicious messages.

The Human Harness: Your Loop Runs First

Every serious agentic coding setup is running a harness right now. Not the model itself, but the machinery around it. The loop it runs in, the tools it can access, the context it receives, and the…

  • Human harness enables effective work with agentic systems
  • Core components: starting cycle, work cycle, decision loop, shared state
  • Example: daily writing routine with word count goal

More from Wednesday 2 September →