{"slug": "how-agents-supercharged-the-hacker-playbook", "title": "How agents supercharged the hacker playbook", "summary": "Google's Threat Intelligence Group's third-quarter report reveals that AI-enabled cyberattacks have evolved from assistance to automation, with adversaries deploying multi-agent frameworks to autonomously carry out attacks, including a mass-credential harvesting attack completed in under six hours. The report highlights that human-in-the-loop latency has dramatically decreased, and threat actors are using autonomous AI to research vulnerabilities, scan infrastructure, and perform exploits, while also targeting proprietary AI IP and using AI across the attack lifecycle.", "body_md": "Agents have turned AI from a tool into a digital coworker. Now, they're doing the same thing for hackers.\n\nOn Tuesday, Google's Threat Intelligence Group released its [third-quarter threat tracking report](https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai), revealing that AI-enabled cyberattacks have evolved from assistance to automation as agents become a growing part of the process. The report finds that \"human-in-the-loop latency\" has dramatically decreased, cutting the time it takes to carry out and defend against cyberattacks.\n\nAccording to the research, Google's threat team observed multiple instances of adversaries deploying multi-agent frameworks and autonomously carrying out parts of attacks, including scanning pipelines and harvesting credentials. In one instance, threat actors compromised a cloud, then planned, built and executed a mass-credential harvesting attack in just under six hours using agents.\n\nThe attack marks a shift from \"passive, endpoint-focused infostealers to offensive agentic harvesting,\" the report notes, as threat actors leverage autonomous AI to research vulnerabilities, scan infrastructure and perform exploits.\n\n\"Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary,\" John Hultquist, chief analyst of the Google Threat Intelligence Group, said in a statement.\n\nAgents aside, the report points to a number of concerning trends:\n\n- AI-coding tools and open-source software, while accelerating software development cycles, have also increased operational risks by widening the attack surface.\n- Adversaries are also targeting proprietary AI IP, including code, prompts, research and the models themselves.\n- AI is being used across the attack lifecycle, including targeting reconnaissance, social engineering, custom malware obfuscation and scaling information operation campaigns.\n- Bad actors are also stealing developer credentials, purchasing compromised AI accounts and breaking into cloud infrastructure to get around AI access costs.\n\n## Our Deeper *View*\n\nGoogle's threat report cements into reality the thing that has the AI industry on edge in the wake of OpenAI's accidental breach of Hugging Face: autonomous, agent-driven cyberattacks are here. Though many fear what agents could do if they go rogue, Google's report paints a potentially more nerve-racking picture: bad actors are harnessing powerful AI tools to systematically do damage. This means that the approach to fighting these attacks has to be two-pronged. The obvious one is fighting fire with fire. Using AI agents to automatically detect and deflect cyberattacks is no longer novel, but a necessity. This, however, could be more effective when done in tandem with more creative means of defense, such as [Cloudflare's recently announced tech](https://www.thedeepview.com/articles/how-cloudflare-s-new-ai-tool-hits-hackers-in-the-wallet) that stalls cyberattacks by making attacks more expensive. What cyber defenders may need most is confidence that they have the tools and partners to defend against AI-enabled attacks, which is what [CrowdStrike emphasized](https://www.thedeepview.com/articles/crowdstrike-forces-ai-agents-to-show-id) at its annual event last week.", "url": "https://wpnews.pro/news/how-agents-supercharged-the-hacker-playbook", "canonical_source": "https://www.thedeepview.com/articles/how-agents-supercharged-the-hacker-playbook", "published_at": "2026-09-08 12:00:00+00:00", "updated_at": "2026-09-08 13:28:20.780109+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "artificial-intelligence"], "entities": ["Google Threat Intelligence Group", "John Hultquist", "OpenAI", "Hugging Face", "Cloudflare", "CrowdStrike"], "alternates": {"html": "https://wpnews.pro/news/how-agents-supercharged-the-hacker-playbook", "markdown": "https://wpnews.pro/news/how-agents-supercharged-the-hacker-playbook.md", "text": "https://wpnews.pro/news/how-agents-supercharged-the-hacker-playbook.txt", "jsonld": "https://wpnews.pro/news/how-agents-supercharged-the-hacker-playbook.jsonld"}}