Under 10 hours. Public API to root credentials to CI/CD to the victim's own AI keys. No zero-day was used.

Palo Alto Networks Unit 42 published the investigation on September 2, 2026: a human attacker who handed tactical execution to frontier AI models running inside attack-specific agentic frameworks.

WHAT ACTUALLY HAPPENED

The chain, compressed into a single working day

Initial access through an exposed public API. Automated reconnaissance mapping the internal architecture. Hard-coded credentials harvested from source repositories. Root administrative credentials pulled from the secrets management system. CI/CD pipelines hijacked, with attempts to modify infrastructure-as-code. Cloud AI infrastructure access keys seized for persistence.

More than 50 MITRE ATT&CK techniques. Unit 42 estimates the same ground would take a coordinated human red team around two weeks.

The forensic signature was distinctive: LLM API calls to multiple agents running in parallel, structured Markdown files used as inter-agent communication, and custom AI-generated scripts orchestrating the operation.

On exit, the actor left behind an 80-page technical audit of the organisation's security failings.

WHY SPEED IS THE ATTACK

Nothing here was novel. No exploit chain you have not seen. What changed is the clock.

Most detection and response programmes are built on human tempo — an attacker who probes, waits, pivots, waits again. Your alerting thresholds, your on-call rotation, your change-approval workflow, your 24-hour containment SLA: all of it assumes days of dwell time to work with.

An agentic loop that monitors, evaluates, acts and re-plans in real time removes that budget entirely. By the time your Tuesday morning triage opens the ticket, the encryption is done.

The defensive question is no longer "can we detect this technique?" It is "can we detect and contain inside a shift?"

WHAT TO DO NOW

PRE-BUILD SYNCHRONISED REVOCATION — one action that rotates secrets and freezes CI/CD pipelines at once, because sequential manual revocation loses this race.

INVENTORY EVERY AI ENDPOINT AND API KEY — model endpoints are now credential stores and persistence points, so rate-limit and monitor them like databases.

HUNT FOR MACHINE TEMPO — bursty API request patterns and rapid authentication state changes are the cheapest agentic-attack signal you have.

LOCK THE PIPELINE — enforce multi-party review and immutable branch protection on infrastructure repositories, so a stolen token cannot rewrite your estate.

Attackers automated their execution. Most defenders still automate only their reporting.

What is your realistic time from first alert to full credential revocation — in hours?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.