<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>AI-enabled intrusion · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/ai-enabled-intrusion/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/ai-enabled-intrusion/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on ai-enabled intrusion, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-26</guid>
<pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs. (moderate confidence) Correction: the extortion campaign ran under human direction, security vendors are among the sources, and Google has not yet seen fully autonomous pipelines in the wild. Government threat reports are still missing from the corpus.</description>
</item>
<item>
<title>Answer revised: How are attackers using AI agents in real operations?</title>
<link>https://agentic-cyber-explorer.pages.dev/questions/how-are-attackers-using-ai-agents/</link>
<guid isPermaLink="false">answer:how-are-attackers-using-ai-agents:2026-09-25</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Key question</category>
<description>Increasingly to run parts of intrusions: providers report agent-driven espionage, extortion and credential theft, and malware that queries LLMs as it runs. (moderate confidence) Revised after twelve threat-intelligence and malware reports from 2024 to September 2026 (Anthropic, ESET, Google, Microsoft with OpenAI, Sysdig and ThreatDown) were added, closing most of the coverage gap the first answer described.</description>
</item>
<item>
<title>Microsoft details Storm-3168's automated destruction of Azure resources through compromised service principals</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-storm-3168-azure-destruction-2026/</link>
<guid isPermaLink="false">event:microsoft-storm-3168-azure-destruction-2026</guid>
<pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft reports that Storm-3168, which it links to the JADEPUFFER operator Sysdig described as agentic ransomware, used two compromised service principals to enumerate an Azure tenant, then attempted more than 150 destructive or credential-collection operations in 35 minutes, deleting most targeted storage accounts along with a Key Vault and Function App. Microsoft says the timing and division of work strongly indicate automated or scripted execution; it did not observe a ransom note or confirm exfiltration. It shows an automated, identity-driven cloud attack by an operator linked to agentic ransomware as seen in the defender's logs, and how independent safeguards such as resource locks limited the damage.</description>
</item>
<item>
<title>ThreatDown finds Carbonato, a Docker botnet that installs an AI agent to run operators’ tasks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/threatdown-carbonato-agent-botnet-2026/</link>
<guid isPermaLink="false">event:threatdown-carbonato-agent-botnet-2026</guid>
<pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>ThreatDown reports a botnet that compromises Docker hosts with unauthenticated APIs, installs the open-source Hermes Agent framework with a replaced persona file, and has the agent carry out tasks sent over Telegram, including collecting AI API keys and other credentials. ThreatDown recovered the operation's toolchain from an exposed registry, with images dating from October 2024 to August 2026, and describes the agent reading command output and deciding next steps in an operator-driven loop. It shows an off-the-shelf agent framework used as a botnet implant, with AI API keys treated as a primary theft target.</description>
</item>
<item>
<title>Mandiant case: hijacked AI coding-assistant session led to poisoned package and worm across ~100 repos</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mandiant-hijacked-coding-assistant-shai-hulud-2026/</link>
<guid isPermaLink="false">event:mandiant-hijacked-coding-assistant-shai-hulud-2026</guid>
<pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach. It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.</description>
</item>
<item>
<title>Google reports attackers moving from prompting to agentic workflows, including a six-hour automated campaign</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-threat-tracker-prompting-to-autonomy-2026/</link>
<guid isPermaLink="false">event:gtig-ai-threat-tracker-prompting-to-autonomy-2026</guid>
<pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group's September 2026 tracker, drawing on Mandiant incident response, reports adversaries shifting from basic prompting to agentic workflows. In one case a suspected financially motivated actor used an AI coding chatbot and agent instruction files on compromised cloud infrastructure to build and run a mass credential-harvesting campaign in under six hours, compromising thousands of third-party credentials. GTIG also reports attackers targeting AI coding assistants and LLM security scanners in software supply-chain compromises, theft of proprietary AI models and data, and a growing underground market for AI accounts. It documents agentic automation in criminal operations from incident response, not only from a model provider's own platform logs.</description>
</item>
<item>
<title>ENISA Threat Landscape 2026 expects more kill-chain phases enabled by AI in 2026</title>
<link>https://agentic-cyber-explorer.pages.dev/events/enisa-threat-landscape-2026-ai/</link>
<guid isPermaLink="false">event:enisa-threat-landscape-2026-ai</guid>
<pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>ENISA's 2026 threat landscape, based on 8,257 incidents in calendar 2025, assesses that AI will highly likely increasingly support malicious operations and that 2026 will likely see more kill-chain phases directly enabled by AI, with possible human-out-of-the-loop proofs of concept. It notes AI applications becoming targets where they hold files, credentials, sessions or development environment access. It is the EU cybersecurity agency's formal assessment of agentic misuse and of agents as targets.</description>
</item>
<item>
<title>MITRE ATLAS adds autonomous attack techniques and case studies of agent-driven intrusions</title>
<link>https://agentic-cyber-explorer.pages.dev/events/mitre-atlas-2026-08-autonomous-attack-techniques/</link>
<guid isPermaLink="false">event:mitre-atlas-2026-08-autonomous-attack-techniques</guid>
<pubDate>Mon, 31 Aug 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>MITRE's August 2026 ATLAS release added techniques describing AI agents acting as attackers, including autonomous reconnaissance, attack-path adaptation, attack orchestration and autonomous exploit development. It also added agent-control mitigations and case studies including the GTG-1002 Claude Code espionage campaign and autonomous OpenAI evaluation agents compromising Hugging Face infrastructure. It extends ATLAS from attacks on AI systems to attacks carried out by AI agents, giving defenders shared identifiers for autonomous intrusion behavior.</description>
</item>
<item>
<title>Sysdig documents JADEPUFFER, a database-extortion intrusion it says an LLM agent ran end to end</title>
<link>https://agentic-cyber-explorer.pages.dev/events/sysdig-jadepuffer-agentic-ransomware-2026/</link>
<guid isPermaLink="false">event:sysdig-jadepuffer-agentic-ransomware-2026</guid>
<pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Sysdig's threat research team reports an operator it calls JADEPUFFER that gained access through a vulnerability in an internet-facing Langflow server (CVE-2025-3248), harvested credentials on that host, then used root database credentials of unknown origin against a separate production database server and ran a database-extortion playbook. Sysdig assesses the operation was driven end to end by an LLM agent, citing self-narrating payloads with natural-language reasoning and rapid adaptive retries, and calls it the first documented case of agentic ransomware. A security vendor's evidence-based case that an agent, not a human-written script, conducted a full extortion intrusion, though the attribution of autonomy rests on code artifacts.</description>
</item>
<item>
<title>Anthropic maps 832 banned accounts onto MITRE ATT&amp;CK and finds AI use moving deeper into attacks</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-mapping-ai-cyber-threats-attack-2026/</link>
<guid isPermaLink="false">event:anthropic-mapping-ai-cyber-threats-attack-2026</guid>
<pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic analyzed 832 accounts it banned for malicious cyber activity between March 2025 and March 2026 and mapped their use of Claude onto MITRE ATT&amp;CK. It reports that the most common AI use was preparation such as writing malware, that use shifted toward activity after initial compromise, and that the share of actors its system rated medium risk or higher rose from 33% to 56% between the two six-month halves. A year of provider data suggests attackers apply AI later in the attack lifecycle, which weakens traditional ways of ranking threat actors by skill.</description>
</item>
<item>
<title>Google Threat Intelligence reports the first criminal zero-day exploit it believes was AI-developed, disrupted before planned mass use</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-ai-developed-zero-day-2026/</link>
<guid isPermaLink="false">event:gtig-ai-developed-zero-day-2026</guid>
<pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group reported that cybercriminals planned a mass-exploitation campaign using a two-factor-authentication bypass in an open-source web administration tool, and assessed with high confidence that an AI model supported discovery and weaponization of the flaw. GTIG worked with the vendor on disclosure and disrupted the activity. The same report describes PRC-nexus actors using agentic frameworks such as Hexstrike and Strix for reconnaissance and vulnerability validation, and Android malware (PROMPTSPY) that calls Gemini to drive the device UI. GTIG calls it the first identified instance of a zero-day exploit it believes was AI-developed by cybercrime actors.</description>
</item>
<item>
<title>Anthropic disrupts a state-sponsored espionage campaign it says was largely executed by Claude Code</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-ai-orchestrated-espionage-gtg-1002-2025/</link>
<guid isPermaLink="false">event:anthropic-ai-orchestrated-espionage-gtg-1002-2025</guid>
<pubDate>Thu, 13 Nov 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic reports that in mid-September 2025 a group it assesses with high confidence to be Chinese state-sponsored used Claude Code inside an attack framework to attempt intrusions into about thirty organizations, succeeding in a small number. The operators got past safeguards by splitting the work into innocuous-looking tasks and claiming to be a security firm doing defensive testing; Anthropic says the AI performed 80 to 90 percent of the campaign, with people at a handful of decision points. It is Anthropic's account of an AI agent executing most of a state espionage operation against real targets, which it tracks as GTG-1002.</description>
</item>
<item>
<title>Anthropic reports Claude Code used to run a data-extortion campaign against at least 17 organizations</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-threat-report-claude-code-extortion-2025/</link>
<guid isPermaLink="false">event:anthropic-threat-report-claude-code-extortion-2025</guid>
<pubDate>Wed, 27 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude. Anthropic presents it as agentic AI carrying out attacks rather than only advising on them, with a human still directing the operation.</description>
</item>
<item>
<title>Google finds government-backed hackers using Gemini for support tasks, not novel capabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/gtig-adversarial-misuse-gemini-2025/</link>
<guid isPermaLink="false">event:gtig-adversarial-misuse-gemini-2025</guid>
<pubDate>Wed, 29 Jan 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Google Threat Intelligence Group analyzed how government-backed hacking and information-operations actors used the Gemini web app. It reports use for research, troubleshooting code and producing content across several attack phases, with Iranian actors the heaviest users, and says it saw productivity gains but no novel capabilities; requests for clearly malicious help drew safety responses. An independent provider reached the same conclusion as Microsoft and OpenAI a year earlier, shortly before reports of agentic misuse began later in 2025.</description>
</item>
<item>
<title>Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-openai-state-actors-llm-use-2024/</link>
<guid isPermaLink="false">event:microsoft-openai-state-actors-llm-use-2024</guid>
<pubDate>Wed, 14 Feb 2024 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted. It is the earliest provider disclosure in this record of named state actors using LLMs, and the baseline that later reports of agentic misuse are measured against.</description>
</item>
<item>
<title>UK NCSC assesses AI will almost certainly increase volume and impact of cyber attacks by 2025</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ai-cyber-threat-assessment-2024/</link>
<guid isPermaLink="false">event:ncsc-ai-cyber-threat-assessment-2024</guid>
<pubDate>Wed, 24 Jan 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NCSC's near-term assessment judged that AI would almost certainly increase the volume and heighten the impact of cyber attacks over the following two years, with uneven effects across actor types. It identified social engineering and reconnaissance as the areas of greatest uplift, and judged that more advanced uses would remain limited to actors with quality data, expertise and resources through 2025. It is a government intelligence-style baseline for how AI changes the cyber threat, against which later assessments (2025, 2026) can be compared.</description>
</item>
</channel>
</rss>
