
Palo Alto Networks’ Unit 42 investigated an intrusion where the attacker used AI agents to carry out the attack — and compressed work a human team would have needed more than two weeks to do into just under ten hours, using more than 50 MITRE ATT&CK techniques. Sherri Davidoff and Matt Durrin unpack what actually happened, starting with a correction: despite the headlines, this was not an autonomous AI. A human directed it. They walk the chain from a breached public website through sub-agents harvesting hard-coded tokens out of code repositories, into the secrets manager, and finally to the attacker turning the victim’s own AI endpoints into attack infrastructure — using the company’s compute power against it. Along the way: why an attempted backdoor in Terraform configurations was the most alarming move in the intrusion, why branch protection stopped an attacker who already held master admin credentials, and why the tactic adversaries use to slip past AI guardrails looks a lot like a Russian ransomware gang’s fake IT recruitment scheme. The thesis isn’t that AI went rogue. It’s that the clock changed, and incident response plans built for a two-week dwell time are now built for the wrong attack. Key Takeaways: Make every key and token in your environment expire. They will not get rotated by default. Set expirations so they cannot stay invisible forever, and track them. Require a second layer of approval for critical infrastructure changes. Branch protection stopped this attacker after they already held master admin credentials. Logging and monitoring are good; prevention is better. Give every AI service in your environment a named owner. Somebody has to be managing the keys and controlling it, so you know where it is. Apply the same controls to your vendors and MSPs. Work these into your next review cycle: how do they manage keys and tokens, do they scan for secrets, do they require second approvals? Run a tabletop against a ten-hour clock. Find out who can actually cut off access to a primary system — who can take it offline, when, and what they need to do it. Resources: Unit 42, “An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation” — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ Anthropic, “Countering misuse of AI: September 2026” — https://www.anthropic.com/threat-intelligence-report-september-2026 GitGuardian, “The State of Secrets Sprawl 2026” — https://blog.gitguardian.com/the-state-of-secrets-sprawl-2026/ Tom Pohl (LMG Security), “Private Keys in Public Places,” DEF CON 31 — https://www.lmgsecurity.com/resources/private-keys-in-public-places-defcon-2023-presentation/ Video of the talk — https://www.youtube.com/watch?v=7t_ntuSXniw
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

AI Collusion? Inside the OpenAI–Hugging Face Attack

Your Security Tools Can Be Used Against You

Zoomsday: Anyone in Your Meeting Can Own You

AI vs. AI: Hacking the Agent, Not the Human
Free AI-powered recaps of Cyberside Chats: Cybersecurity Insights from the Experts and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.