Incident2026-09-02

An attacker used AI agents to breach an enterprise network in under ten hours. Palo Alto Networks' Unit 42 investigated the intrusion and published its findings. The attacker set the objectives while agents mapped the network, scraped code repositories and took root credentials. They also triggered unauthorised build pipelines and stole cloud keys. With those keys they ran the victim's own AI services as attack infrastructure. No zero-day exploit or elite tradecraft was involved, only speed. Branch-protection controls blocked an attempt to plant backdoors in infrastructure code. The agent was also told to leave an 80-page audit of the company's weaknesses. Unit 42 advises automated containment playbooks, inventories of every model endpoint and API key, and mandatory multi-party code review. It expects more attackers to adopt agents.

What changed

Comparable intrusions took human operators around two weeks.

What it unlocks

Defenders can hunt for agent-specific traces such as structured Markdown files, Python caches and paired asset folders.

  • under 10 hours end to end
  • 50+ MITRE ATT&CK techniques
  • ~2 weeks of human effort compressed
  • 80-page report left behind

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.