An expert-authored International AI Safety report says AI agents are increasingly being used to support multiple stages of cyberattacks, with notable gains over the past year in vulnerability discovery and malicious code generation. The report cites results from DARPA’s AI Cyber Challenge where finalist systems autonomously identified 77% of synthetic vulnerabilities, and notes criminal use of AI tooling (e.g., HexStrike AI) to accelerate exploitation soon after public vulnerability disclosures; it also describes a growing market for “weaponized” models that can generate ransomware and data-stealing code at low monthly cost.
Despite these advances, the report assesses that fully autonomous, end-to-end, multi-stage attacks are not yet commonly observed because current AI systems struggle to reliably execute long, complex sequences without human oversight, including poor error recovery and irrelevant command execution. Separately, CSO Online highlights risk-management concerns that large numbers of deployed AI agents could “go rogue,” underscoring governance and control challenges as organizations operationalize agentic AI at scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSO Online published a news item warning that 1.5 million AI agents are at risk of 'going rogue,' framing the issue as a security and risk-management concern. The reference provides no additional dated incident details beyond the publication itself.
The report cited DARPA's AI Cyber Challenge, where finalist systems autonomously identified 77% of synthetic vulnerabilities, and described a growing market for weaponized AI models that can aid ransomware and data-stealing malware development for as little as $50 per month. It also noted observed use of AI by Chinese cyberspies and tools such as HexStrike AI to help exploit critical vulnerabilities soon after disclosure.
An International AI Safety report authored by more than 100 experts concluded that AI systems are increasingly being used by criminals and state-linked operators to assist with multiple stages of cyberattacks, while still falling short of fully autonomous end-to-end operations. The report said progress over the prior year improved AI capabilities in areas such as vulnerability discovery and malicious code generation, but noted reliability limits in long, complex attack chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.