Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Summary
Threat actors are using autonomous AI agents (AI systems that can independently perform multiple tasks) to steal credentials and compromise cloud environments at unprecedented speed, with one group harvesting thousands of credentials in just six hours. Attackers are targeting AI assets like proprietary models and API credentials (secret keys that allow access to services) across healthcare, government, and media sectors, and are deploying credential-stealing malware like DUSTMAKER that uses prompt injection (tricking AI by hiding instructions in its input) to evade defenses. This represents a broader shift where criminals are leveraging AI-assisted tools to accelerate attacks faster than security teams can respond.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
First tracked: September 8, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%