AI ‘Machine Speed’ Cuts 2-Week Attack Down to 10 Hours

Cyberattacks Just Got a Whole Lot Faster with the Help of AI

A recent incident has demonstrated how attackers can use artificial intelligence (AI) agents to breach an enterprise network in under 10 hours, a speed that would typically take two weeks or more. This rapid attack was orchestrated by a human attacker using frontier AI to automate tasks and coordinate a large-scale breach.

The attacker used AI agents to blast through the company’s security layers, each targeting a different layer of defense to achieve a shared goal. The impact was on par with a coordinated effort from multiple red teams, which would normally take human operators around two weeks to accomplish. This incident highlights the growing threat of AI-assisted attacks and serves as a stark warning for organizations about the speed at which attackers can orchestrate a team of agents to compromise their networks and assets.

The attack was notable not only for its speed but also for its operational efficiency. The attacker left tactical execution to AI agents that monitored, evaluated, acted, and re-planned in real-time, increasing speed throughout the attack chain. This level of coordination is made possible by the use of specialized agents working in parallel, sharing findings and adapting while a human sets objectives and makes consequential calls.

The shift from automating individual tasks such as writing phishing emails or analyzing binaries to a group of agents working together to achieve malicious goals is a significant evolution in AI assistance. As Rickard Carlsson, CEO of AI security firm Detectify, observes, “What Unit 42 is describing is a set of specialized agents working in parallel, sharing findings and adapting, while a human sets the objectives and makes the consequential calls.” In this way, the attack process has become a workflow.

The operational timeline of the attack was varied and began with the threat actor breaching a public API endpoint to tunnel into the network and deploy an automated reconnaissance agent. The adversary then harvested secrets using sub-agents that combed enterprise code repositories, extracting hard-coded tokens and service passwords. These exposed tokens were used to infiltrate the secrets management system and obtain master administrative credentials to gain root system access.

The attacker also took control of an enterprise code application and exfiltrated cloud access keys, which were then used to turn the victim’s AI endpoints into post-compromise infrastructure for future malicious activity. This level of sophistication is a stark reminder that attackers are increasingly using AI to automate tasks and coordinate large-scale breaches.

In light of this incident, organizations should be aware of the growing threat of AI-assisted attacks and take steps to protect themselves. This includes implementing robust security measures such as monitoring network traffic for anomalies and staying up-to-date with the latest security patches. It also means being aware of the potential for attackers to use AI to automate tasks and coordinate large-scale breaches. By understanding these threats, organizations can better prepare themselves to defend against them and minimize the risk of a successful attack.


Source: Dark Reading — 2026-09-03