Security News

Cybersecurity news aggregator

CRITICAL Attacks Dark Reading

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

  • What: AI agents drastically reduce attack time from 2 weeks to 10 hours
  • Impact: Enterprises face increased risk from AI-powered attacks
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES THREAT INTELLIGENCE CYBER RISK VULNERABILITIES & THREATS NEWS AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers. Elizabeth Montalbano,Contributing Writer September 3, 2026 4 Min Read SOURCE: IMAGE FLOW VIA SHUTTERSTOCK An attacker used artificial intelligence (AI) agents to blast through an enterprise network in less than 10 hours, significantly reducing the typical two-week time span an attack of similar magnitude would have taken. Researchers from Palo Alto Networks' Unit 42 responded to the incident, in which a human attacker used frontier AI to breach an enterprise network autonomously as part of a "machine-speed" ransomware attack, according to a report published Wednesday. During the attack, which took mere hours, the attacker harvested credentials, seized root access, hijacked CI/CD pipelines, and even turned the victim’s own AI infrastructure against it. "The agents breached the company's security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal," Unit 42 researchers wrote in the report. "The impact was at the scale of a coordinated effort from multiple red teams, which would normally take human operators around two weeks." Related:Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users The incident is a stark warning for organizations about the speed at which attackers can orchestrate a team of agents to compromise their networks and assets. AI-Driven Coordination Makes the Difference Indeed, AI-assisted attacks are becoming more common, but what made this attack stand out was the operational efficiency the attacker achieved using AI "without the need for a novel zero-day or super elite tradecraft," the researchers wrote. "The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain," they wrote. The attacker also directed the agent to leave behind a "report" on the organization's security posture, which came in the form of an 80-page technical audit. The attack demonstrates an evolution in AI assistance from using it to automate individual tasks such as writing phishing emails, analyzing binaries, and generating scripts, to a group of agents working in a coordinated way alongside a human attacker to achieve a set of malicious goals, observes Rickard Carlsson, CEO of AI security firm Detectify. “The shift here is orchestration," he says. "What Unit 42 is describing is a set of specialized agents working in parallel, sharing findings and adapting, while a human sets the objectives and makes the consequential calls." In this way, "the attack process has become a workflow," Carlsson adds. AI Agents as Special Ops Team Indeed, the operation appears to have been structured less like a conventional hacker working through a checklist and more like an automated team of specialized operators, with the adversary running the attack using current AI-enabled software development processes, the researchers said. Related:Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency Some of the processes used by the attacker included LLM calls to multiple frontier AI agents; structured markdown files passed between agents and sessions; and custom scripts that were AI-generated to manage dynamic operations. The agents worked together to process the results of their actions, decide what to do next, and re-plan in real time, the researchers noted. Malicious activity covered in the 10-hour operational timeline was varied and began with the threat actor breaching a public API endpoint to tunnel into the network and deploy an automated reconnaissance agent to map internal microservices. The adversary also harvested secrets using sub-agents that combed enterprise code repositories, extracting hard-coded tokens and service passwords. The attacker then used these exposed tokens to infiltrate the secrets management system and obtain master administrative credentials to gain root system access. They also took control of an enterprise code application and exfiltrated cloud access keys. These keys were then used to turn the victim's AI endpoints into post-compromise infrastructure for future malicious activity, the researchers wrote. Related:Anthropic Users Hit by Infostealer Attacks, Session Thefts "What's striking is how ordinary the underlying weaknesses were: an exposed API, hardcoded credentials, tokens opening paths into sensitive systems," Carlsson observes about the security gaps exploited in the attack. "The agents didn't discover a new class of vulnerability; they moved through existing exposures faster and more systematically. The intelligence was in the coordination, not the exploitation." Match AI's Pace, Adaptability to Defend Overall, the attack "exposes how an attacker who understands how to deploy frontier AI agents effectively can dramatically speed up the pace of their attack," the researchers wrote, and they expect that attackers will increasingly add AI agents to their tool sets. This means that defending against automated agents loops will require "matching the speed and adaptability of AI-driven attacks," they added. This will require enterprises "to make security continuous rather than periodic," Carlsson observes. "Repositories, pipelines, infrastructure-as-code and secrets management all need to be treated as part of the attack surface." They also should make credentials short-lived, and inventory AI endpoints and integrations, as well as automate containment "so compromised access can be shut down quickly," Carlsson adds. Organizations also should make their security savvy to the automation that AI-assisted attacks provide by detecting behavioral loops, according to Unit 42. "Hunt for operational loops including bursty API requests, rapid 401/200 HTTP state shifts, parallel authentications and sudden model usage from unexpected identities," the researchers advised defenders. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is

Share this article