Unit 42: AI agents sped enterprise breach
Palo Alto Networks’ Unit 42 published on September 2, 2026 an incident-response writeup of a human-directed intrusion where the attacker said they used frontier AI models and agentic frameworks to automate execution — compressing work Unit 42 likens to multi–red-team effort (normally ~two weeks) into under 10 hours, spanning more than 50 MITRE ATT&CK techniques without a novel zero-day. After initial access, agents mapped the environment, harvested secrets from code repos, obtained master credentials via the secrets manager, abused CI/CD for cloud keys, and used stolen keys against the victim’s own AI endpoints; an agent also left an ~80-page technical security audit. This is Unit 42’s investigation summary (updated to clarify intrusion, not ransomware), not a how-to, not Google Mandiant’s separate six-hour campaign, and not a product launch.