Cybersecurity experts are warning that island hopping attacks, traditionally associated with network intrusions, are now evolving to target cloud environments, APIs, and artificial intelligence tools. Attackers are leveraging these platforms to hijack organizational infrastructure, enabling them to launch further attacks against customers, partners, and government agencies. This new wave of supply chain threats is characterized by persistent access, with adversaries embedding themselves deeply and for extended periods through techniques such as access mining and manipulation of agentic AI.
To address these risks, organizations are being urged to update their third-party risk management practices, including conducting comprehensive AI security assessments that account for model poisoning and persistence threats. Strengthening third-party certifications and revising service-level agreements are also recommended to mitigate the impact of these advanced attacks. As the adoption of AI accelerates, the potential for AI systems to be exploited as vectors for island hopping underscores the need for heightened vigilance and proactive defense strategies.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.