{"data":{"id":"96ce32f9-4b36-47d2-8a42-5b4a9ba85ab7","title":"Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours","summary":"Threat actors are using autonomous AI agents (AI systems that can independently perform multiple tasks) to steal credentials and compromise cloud environments at unprecedented speed, with one group harvesting thousands of credentials in just six hours. Attackers are targeting AI assets like proprietary models and API credentials (secret keys that allow access to services) across healthcare, government, and media sectors, and are deploying credential-stealing malware like DUSTMAKER that uses prompt injection (tricking AI by hiding instructions in its input) to evade defenses. This represents a broader shift where criminals are leveraging AI-assisted tools to accelerate attacks faster than security teams can respond.","solution":"N/A -- no mitigation discussed in source.","labels":["security","safety"],"sourceUrl":"https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html","publishedAt":"2026-09-08T13:48:16.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","model_poisoning","data_extraction","supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google","Google Threat Intelligence Group","Gemini","PyPI","npm","Docker Hub"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-08T13:48:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}