Google’s research, released today, details a concerning trend. Advanced adversaries are now integrating agentic AI and AI-enabled automation into their cyber operations, moving well beyond earlier uses of large language models for reconnaissance or social engineering.
A Six-Hour Breach
This shift could significantly compress the window defenders have for detection and response. One incident from the second quarter of 2026 shows just how fast that window is closing. Threat actors compromised a cloud resource, then executed an agent-enabled mass credential-harvesting campaign in under six hours.
Attackers are now testing multi-agent frameworks capable of managing scanning pipelines, handling operational errors, and conducting credential harvesting with minimal human input. Google’s research describes this as an incremental shift rather than a sudden one, but the direction is clear.
State-backed groups and criminal operators are already layering AI across multiple stages of an attack. This includes:
- Target reconnaissance
- Social engineering lures
- Malware obfuscation
- Vulnerability research and exploit prototyping
- Post-access troubleshooting
Adversaries are drawing on both commercial and open-weight AI models to support this work. Google has not observed fully autonomous zero-day exploitation against real-world targets yet. Instead, AI is being layered onto existing methods, increasing attack speed and reducing how much direct human involvement is needed. Security teams should expect familiar attack techniques to arrive faster and at greater scale, not necessarily new techniques altogether.
Open Source Under Pressure
The research also flags rising risk in AI-assisted software development, with open-source ecosystems proving particularly exposed. Google has tracked a financially motivated actor known as UNC6780, also called TeamPCP, which carried out large-scale compromises affecting ecosystems like PyPI, npm, and Docker Hub.
These attacks went further than typical package poisoning. They included efforts to manipulate AI coding assistants and security scanners directly, using techniques like prompt injection to influence how AI systems analyzed malicious code. That adds a new layer to software supply chain attacks, since targeting developer tools lets attackers interfere earlier in the creation process, before code even ships. AI systems embedded in development workflows are now effectively part of the attack surface.
The Models Themselves Are Targets
Attackers aren’t only using AI tools. They’re going after AI infrastructure directly. Google observed attempts to steal proprietary AI models, source code, prompts, and API credentials, along with compromised cloud environments being repurposed for unauthorized AI workloads.
This suggests AI assets themselves have become valuable enough to target on their own terms, driven by cyber espionage, extortion, and theft of computing resources. The findings draw on Mandiant incident response work alongside Google’s broader threat tracking.
Hashlytics Take
The six-hour credential harvesting campaign is the detail that matters here, not the general warning about AI-assisted attacks. Most coverage of AI in cybercrime focuses on better phishing emails or faster malware writing, which is real but incremental. What Google is actually describing is attackers handing off entire operational sequences, scanning, error handling, credential harvesting, to a system that runs with minimal supervision. That’s a different threat model than AI making attackers more efficient at things they already did manually. Defenders built their response timelines around human-paced attacks. An agent that self-corrects and keeps moving doesn’t wait for anyone’s incident response plan to catch up.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



