AI speeds up attacks to 10 hours
An attacker used a team of AI agents to break into a company's network and finish what would normally be a two-week attack in under 10 hours. The AI agents stole login credentials, gained root-level control, hijacked the company's software deployment pipeline, and turned the victim's own AI systems against it.
- Report priority
- Medium
What is known
A human attacker directed several AI agents to work at once, each one probing and attacking a different layer of the company's defenses, monitoring results and adjusting tactics in real time instead of waiting on a person to plan each step.
What to do
The takeaway is that security teams should read Unit 42's incident report and plan defenses assuming an intrusion can now move through credential theft, privilege escalation, and CI/CD compromise in hours instead of weeks.
Reported details
Palo Alto Networks' Unit 42 team responded to a real breach where a human attacker set a team of AI agents loose on an enterprise network. The agents worked through the company's defenses layer by layer, harvesting credentials and escalating to root access. They hijacked the company's software build and deployment pipeline and turned its own AI infrastructure against it. The attacker then had the agents compile an 80 page technical report on the company's security weaknesses.
Unit 42 says the attacker did not rely on a novel zero-day or elite tradecraft, only known techniques executed and coordinated by AI agents fast enough to compress a roughly two-week, multi-stage intrusion into under 10 hours. Within that window the agents harvested credentials, escalated to root access, compromised CI/CD pipelines, and repurposed the victim's own AI infrastructure, then produced an 80-page write-up of the target's security posture. Unit 42 frames this as a shift from AI assisting single tasks like phishing emails or script writing toward AI agents coordinating a full attack chain alongside a human operator.