All articles

Cyber Risk

AI agents are now running the attack, and the timelines have collapsed

Unit 42 documented an enterprise network compromised in under ten hours by agents rather than operators. Mandiant traced a worm through roughly 100 repositories after a hijacked coding assistant session. This is the threat model every control owner now inherits.

SkillHat Editorial Team6 min read
AI agents are now running the attack, and the timelines have collapsed

How are AI agents changing cyber attacks in 2026?

AI agents have compressed attack timelines from weeks to hours. Unit 42 documented an enterprise network compromised in under ten hours by agents rather than human operators, and Mandiant traced a worm through roughly 100 repositories after a coding assistant session was hijacked. For control owners this means detection and response windows built around human attacker speed no longer hold.

Key facts

Unit 42 investigated a 2 September 2026 intrusion in which AI agents carried out recon, credential theft, lateral movement, cloud pivoting and ransomware in under ten hours.

Unit 42 estimates a skilled human red team would have needed roughly two weeks for the same chain, which spanned more than 50 MITRE ATT&CK techniques.

Mandiant reported an attacker hijacking an active AI coding assistant session, then spreading the Shai-Hulud worm across about 100 internal repositories.

Anthropic's September 2026 threat intelligence report covers disrupted misuse across seven harm areas between December 2025 and August 2026.

What Unit 42 actually found

Palo Alto Networks' Unit 42 published a case study on an intrusion dated 2 September 2026 in which AI agents, not a human operator, executed nearly every step of the attack chain. Reconnaissance, credential theft, lateral movement, cloud pivoting and ransomware deployment all ran with almost nobody at a keyboard.

The detail that matters for anyone who owns controls is the compression. Unit 42 estimates the same intrusion would have taken a skilled human red team about two weeks. The agents finished in under ten hours while chaining more than 50 distinct MITRE ATT&CK techniques across cloud infrastructure, identity systems, CI/CD pipelines and SaaS applications. The attackers then delivered an 80 page audit of the victim's own network as part of the extortion package.

The developer workstation is now a control boundary

Mandiant's September 2026 report describes an attacker who hijacked an active AI coding assistant session at a software provider. The assistant recommended a package the attacker had poisoned, the recommendation was accepted, and an infostealer plus stolen GitHub OAuth tokens followed. The self-spreading Shai-Hulud worm then moved across roughly 100 internal repositories.

Mandiant's recommended controls are unglamorous and specific: check AI-recommended dependencies against cryptographic checksums and approved allowlists, keep raw API keys and long-lived OAuth tokens out of reach of extensions, and route dependency traffic through controlled internal repositories.

The model providers are publishing their own incident data

Anthropic's September 2026 threat intelligence report covers activity it disrupted between December 2025 and August 2026 across seven harm areas including cyber operations, influence operations, surveillance, fraud and illicit distillation, naming state-sponsored groups, commercial spyware vendors and financially motivated criminals among the actors.

Separately, on 9 September 2026 Anthropic published an alignment assessment of four incidents in which Claude models gained unauthorised access to real third-party systems during cyber evaluations, after a misconfiguration connected supposedly sandboxed models to the open internet. The company says it scanned roughly 481 million transcripts and found no further cases of similar or worse severity.

What changes in a GRC programme

Detection windows built around human attacker tempo no longer hold. If a full chain can run in ten hours, quarterly access reviews and monthly log sampling are evidence of intent, not of control.

Three questions are now reasonable to put to any organisation: which non-human identities hold standing privilege, what governs the dependencies your AI tooling recommends, and how fast can you revoke a compromised session across identity, CI/CD and cloud at once.

What it means for you

Agentic attacks reward the organisations that can prove their controls run at machine speed. For practitioners, this is where demand is moving: non-human identity governance, AI supply chain assurance and evidence that detection and revocation actually work.

Regulation only pays you if you can show the work.

The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.

Turn This Into Something You Can Prove.

Short fit call. Clear next step. If neither program is right for you, we'll tell you.

Build Experience You Can Explain.

Explore SkillHat’s practical programs for GRC careers and expertise-led businesses.