September 2, 2026
Unit 42: AI agents compressed a 2-week enterprise breach into under 10 hours, then delivered an 80-page security audit
Palo Alto Networks Unit 42 responded to an incident in which a human attacker used frontier AI models and custom agentic frameworks to breach an enterprise network in under 10 hours, autonomously executing more than 50 MITRE ATT&CK techniques. AI agents performed reconnaissance through a public API endpoint, mapped internal microservices, scraped code repositories for credentials, compromised the secret-management system for master admin access, and pivoted across cloud, identity, CI/CD, container, and SaaS environments. The attack replicated what multiple coordinated red teams would normally take two weeks to accomplish. In an unusual move, the attacker left the victim an 80-page security audit documenting every exploited gap.
Agentic attackers generate highly anomalous API call patterns: rapid credential sweeps across connected services, lateral movement through cloud and SaaS APIs, and out-of-baseline access across identity and CI/CD pipelines. Salt's agentic API monitoring establishes behavioral baselines per identity and integration, flagging these patterns in minutes rather than after the attack completes.
Agentic/MCP
Read full story