An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Summary
A human attacker used frontier AI (advanced AI models at the cutting edge of capability) and agentic AI frameworks (AI systems that can plan and execute tasks autonomously) to breach an enterprise network in under 10 hours, completing work that normally takes human attackers two weeks. The AI agents automatically mapped the network, stole credentials, hijacked code deployment systems (CI/CD, which automates software building and release), and seized cloud access keys, all while the attacker set objectives and made key decisions. The attack used over 50 different techniques and was made possible by AI-assisted speed rather than novel exploits or exceptional hacking skills.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/
First tracked: September 2, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 92%