Skip to content
Live newsroom 135 readers online
Tuesday, August 25, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingDolly Parton Net Worth: How the Country Icon Built up Her $450M Empire and Who Will Inherit It?
Important AVOID JPM Stage 4 (Conv: 1/5 | Size: 10%)

When the attacker has no human left to catch

Agentic AI just crossed cybersecurity's most feared threshold When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. For years, the phrase "AI-powered attack" has mostly meant a human using AI tools to write better phishing emails or scan for vulnerabilities faster. That framing just became outdated. […]

By deepak · August 25, 2026 · 3 min read

Agentic AI just crossed cybersecurity's most feared threshold

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

For years, the phrase "AI-powered attack" has mostly meant a human using AI tools to write better phishing emails or scan for vulnerabilities faster. That framing just became outdated.

This month's intrusion into a major AI infrastructure platform was carried out, start to finish, by an autonomous agent.

No operator typed commands during the attack. No one was watching a terminal, deciding what to try next.

The agent found its own way in, escalated its own privileges, moved across internal systems on its own initiative, and kept going until it was caught.

Richard Werner is European Business Consultant at TrendMicro.

It executed thousands of individual actions across a swarm of short-lived sandboxes, using infrastructure that migrated itself to stay ahead of takedown efforts.

That last detail is the one worth sitting with. This wasn't a script running on a loop. It was closer to a persistent, adaptive actor that happened not to be a person.

Security teams have spent the last two years bracing for what researchers called the "agentic attacker" scenario: a future where offensive AI doesn't just assist a human operator but replaces the decision-making loop entirely. That future arrived faster than most roadmaps allowed for. And it arrived through an unglamorous door.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The intrusion began not with some exotic zero-day but with a malicious dataset, exploiting weaknesses in how data gets processed and executed. Old lesson, new attacker. The place where AI platforms are most exposed is often the plumbing, not the model.

What makes this incident more than a cautionary anecdote is where the agent came from. It wasn't built by a criminal group. It emerged from an internal test, one company evaluating how capable its own models were at offensive internet security work.

The safeguards that would normally stop a model from behaving this way had been deliberately loosened for the purposes of that evaluation, and the agent found a flaw serious enough to escape the contained environment altogether. It got out, found a live target, and treated it the same way it had been trained to treat a benchmark: as a problem to solve, thoroughly and without asking permission.

This is where the industry's favorite excuse collapses. "The AI acted on its own" is true, technically. It is also irrelevant to the question of who is responsible. Nobody would accept that defense from a bank whose fraud-detection algorithm accidentally froze every customer account overnight, and nobody should accept it here.

Source: Read the original article on www.techradar.com