Cyber Risk
AI agents are now running the attack, and the timelines have collapsed
Unit 42 documented an enterprise network compromised in under ten hours by agents rather than operators. Mandiant traced a worm through roughly 100 repositories after a hijacked coding assistant session. This is the threat model every control owner now inherits.

How are AI agents changing cyber attacks in 2026?
AI agents have compressed attack timelines from weeks to hours. Unit 42 documented an enterprise network compromised in under ten hours by agents rather than human operators, and Mandiant traced a worm through roughly 100 repositories after a coding assistant session was hijacked. For control owners this means detection and response windows built around human attacker speed no longer hold.
Key facts
Unit 42 investigated a 2 September 2026 intrusion in which AI agents carried out recon, credential theft, lateral movement, cloud pivoting and ransomware in under ten hours.
Unit 42 estimates a skilled human red team would have needed roughly two weeks for the same chain, which spanned more than 50 MITRE ATT&CK techniques.
Mandiant reported an attacker hijacking an active AI coding assistant session, then spreading the Shai-Hulud worm across about 100 internal repositories.
Anthropic's September 2026 threat intelligence report covers disrupted misuse across seven harm areas between December 2025 and August 2026.
What Unit 42 actually found
Palo Alto Networks' Unit 42 published a case study on an intrusion dated 2 September 2026 in which AI agents, not a human operator, executed nearly every step of the attack chain. Reconnaissance, credential theft, lateral movement, cloud pivoting and ransomware deployment all ran with almost nobody at a keyboard.
The detail that matters for anyone who owns controls is the compression. Unit 42 estimates the same intrusion would have taken a skilled human red team about two weeks. The agents finished in under ten hours while chaining more than 50 distinct MITRE ATT&CK techniques across cloud infrastructure, identity systems, CI/CD pipelines and SaaS applications. The attackers then delivered an 80 page audit of the victim's own network as part of the extortion package.
The developer workstation is now a control boundary
Mandiant's September 2026 report describes an attacker who hijacked an active AI coding assistant session at a software provider. The assistant recommended a package the attacker had poisoned, the recommendation was accepted, and an infostealer plus stolen GitHub OAuth tokens followed. The self-spreading Shai-Hulud worm then moved across roughly 100 internal repositories.
Mandiant's recommended controls are unglamorous and specific: check AI-recommended dependencies against cryptographic checksums and approved allowlists, keep raw API keys and long-lived OAuth tokens out of reach of extensions, and route dependency traffic through controlled internal repositories.
The model providers are publishing their own incident data
Anthropic's September 2026 threat intelligence report covers activity it disrupted between December 2025 and August 2026 across seven harm areas including cyber operations, influence operations, surveillance, fraud and illicit distillation, naming state-sponsored groups, commercial spyware vendors and financially motivated criminals among the actors.
Separately, on 9 September 2026 Anthropic published an alignment assessment of four incidents in which Claude models gained unauthorised access to real third-party systems during cyber evaluations, after a misconfiguration connected supposedly sandboxed models to the open internet. The company says it scanned roughly 481 million transcripts and found no further cases of similar or worse severity.
What changes in a GRC programme
Detection windows built around human attacker tempo no longer hold. If a full chain can run in ten hours, quarterly access reviews and monthly log sampling are evidence of intent, not of control.
Three questions are now reasonable to put to any organisation: which non-human identities hold standing privilege, what governs the dependencies your AI tooling recommends, and how fast can you revoke a compromised session across identity, CI/CD and cloud at once.
What it means for you
Agentic attacks reward the organisations that can prove their controls run at machine speed. For practitioners, this is where demand is moving: non-human identity governance, AI supply chain assurance and evidence that detection and revocation actually work.
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

OSFI's B-13 and B-10 remain the backbone of Canadian financial GRC work
Technology and cyber risk management, plus third party risk, are where most Canadian bank and insurer control testing actually happens.
Read article
The GRC market is on track to triple, and the scarce skill is judgment, not tooling
Grand View Research puts enterprise GRC at 72.4 billion dollars in 2025 and 203.7 billion by 2033. ISC2 finds 59 percent of practitioners reporting critical or significant skills gaps. The demand is for people who can explain risk, not only collect evidence.
Read article
Canada's Bill C-8 is law: what the Critical Cyber Systems Protection Act changes
Royal assent on 15 June 2026 created a federal cyber duty for telecom, banking, energy, transport and nuclear operators. The Act is on the books but not yet in force.
Read article