A human attacker used frontier AI agents to breach an enterprise network and seize root access in under 10 hours, per Palo Alto Networks' Unit 42
Unit 42 says an attacker directed AI agents through more than 50 chained attack techniques to breach a company's network and seize root access in under 10 hours, a scale of intrusion that would normally take human red-team operators about two weeks. Source: Unit 42 (Palo Alto Networks $PANW), Dark Reading.
Palo Alto Networks' Unit 42 says a human attacker used frontier AI models paired with custom agentic frameworks to breach an enterprise network largely on their own, compressing an intrusion that would normally take human red-team operators about two weeks into under 10 hours. The agents chained more than 50 MITRE ATT&CK techniques into one automated loop: breaching a public-facing web service to get in, mapping the internal network, scraping code repositories for hardcoded credentials, infiltrating the secrets-management system to seize root access, and hijacking the company's software pipeline to steal cloud access keys. An attempt to plant backdoors in the company's infrastructure code was blocked by branch-protection controls. Using the stolen cloud keys, the attacker also took over the victim's own AI infrastructure to support further attacks, and had the agents produce an 80-page technical audit of the company's security gaps before leaving. The attacker told investigators during ransom negotiations that they relied on the AI agents throughout the intrusion; Unit 42 later updated its report to clarify this was an intrusion, not a confirmed ransomware attack. No zero-day vulnerability was involved, researchers say the attack succeeded through ordinary security gaps executed at unusual speed. Sources: Unit 42 (Palo Alto Networks $PANW), Dark Reading.