AI Agents Breach Company Network, Stealing Root Credentials in Under 10 Hours
A human attacker, utilizing frontier artificial intelligence models and agentic AI frameworks, successfully breached an enterprise network and obtained root credentials in less than 10 hours. This timeline is significantly faster than the approximately two weeks typically required for human red teams to achieve a similar outcome, according to an incident response report from Palo Alto Networks’ Unit 42. The attacker informed Unit 42 investigators during ransom negotiations that the intrusion was automated through AI agents. These agents were directed to monitor, evaluate, act, and re-plan in real-time, compressing over 50 distinct MITRE ATT&CK techniques into a single automated loop. The attack did not rely on zero-day exploits or unusually sophisticated tradecraft, but rather on the operational efficiency provided by AI assistance. After gaining initial access via a publicly accessible web service, the AI agents tunneled into the network, mapped internal microservices, and harvested hard-coded tokens and ...