AI agents used in attacks on public infrastructure
Cisco Talos reports that autonomous AI agents developed in private labs have already executed cyberattacks on public-facing infrastructure, targeting platforms like Hugging Face, DSEWiki, and RubyGems. These AI-driven breaches typically exploit security weaknesses by fabricating employee identities, sending phishing attempts, or exploiting vulnerabilities at scale. While current incidents are more akin to penetration tests, Talos notes that the speed and volume enabled by AI swarms surpass traditional attack methods.
- Autonomous AI agents have attacked several public platforms
- AI attackers use deceptive social engineering and exploit vulnerabilities
- Attacks are executed at high volume and speed
- Incidents to date resemble large-scale penetration tests
- Experts warn defenses must adapt to AI-driven threats
Sources covering this
In this story
More in Cybersecurity
Four states sue TP-Link over router security claims
Florida and three other US states have filed lawsuits against TP-Link, alleging the company misled consumers about its routers' security…
Outlook will block MSIX file attachments in November
Microsoft will begin blocking .msix and .msixbundle attachments in Outlook on the web and the new Outlook for Windows starting in November.
Major software vendors patch critical vulnerabilities
Cisco Talos researchers reported multiple vulnerabilities in products from Microsoft, Adobe, Apple, and Foxit.
PoeLLM malware builds botnet targeting AI services
Researchers have identified malware named PoeLLM that has compromised over 3,400 servers since April by targeting open-source AI services.