AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.
Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.
Help Net Security
Publisher
Sep 8, 2026 at 1:44 PM UTC · Updated bir gün önce · 3 dk okuma


(Source: Google)
The report draws on Mandiant incident response engagements, threat actor tracking, and live platform defenses. Researchers observed attackers moving from basic prompts toward workflows where AI systems handle several connected tasks.
A six-hour credential theft campaign
In Q2 2026, Mandiant investigated a suspected financially motivated threat actor that compromised an organization’s cloud infrastructure and deployed an autonomous multi-agent framework.
The attacker used an AI coding chatbot, a prompt, and agent instructions to plan, build, and execute a mass credential-harvesting campaign in less than six hours. Thousands of third-party credentials were compromised.
“The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention,” GTIG researchers wrote.
The attacker operated from the victim’s cloud infrastructure, which allowed attack traffic to pass through legitimate IP addresses.
Article Intelligence
Topics
Regulation Signal
in progressUpdated bir ay önce
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
