Security leaders are warning that agentic AI is shifting the threat model by turning authenticated, permissioned access into a primary attack path. Symantec argues that controls designed around human behavior and pace (e.g., static credentials, overprivileged access, and human-scale monitoring) are poorly suited to autonomous agents that can operate at machine speed, rapidly probing APIs and systems and using existing permissions to move laterally. The post highlights proof-of-concept and prior incidents where agent behavior can be manipulated to expose secrets (e.g., coercing a voice agent to reveal an API key), framing an agent’s own decision logic as an exploitable attack surface that drives the need for redesigned authorization and tighter identity/access models.
Microsoft threat intelligence reporting, echoed in an interview with The Register, describes threat actors using AI agents to automate “janitorial” tasks that materially increase operational tempo—especially reconnaissance and attack infrastructure setup/management. Sherrod DeGrippo (Microsoft) said autonomous agents can be tasked to scan target netblocks, inventory compromised environments, and accelerate standing up infrastructure, and Microsoft has observed North Korea-linked Coral Sleet leveraging development platforms to quickly create and manage infrastructure supporting campaigns (including activity associated with the fake IT worker scam). Together, the reporting indicates agentic AI is already being applied to make attacks better, bigger, and faster, with defenders needing to account for automated, high-velocity activity that may originate from valid credentials and legitimate tooling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Security.com expert analysis argued that agentic AI changes the threat model by acting as an authenticated insider, exploiting business-logic weaknesses and machine identities rather than relying on traditional software exploits. It recommended moving to ephemeral just-in-time credentials and centralized, context-aware authorization to mitigate these risks.
Microsoft GM of global threat intelligence Sherrod DeGrippo said agentic AI is enabling cybercriminals and nation-state actors to outsource reconnaissance and attack-infrastructure management, increasing efficiency, scale, and speed. She also noted defenders are seeing AI-generated malware and malware that incorporates AI functions, though fully autonomous attacks are not yet a reality.
Microsoft Threat Intelligence reported observing the North Korea-linked group Coral Sleet using development platforms to rapidly create and manage infrastructure at scale for staging, testing, and command-and-control operations. The activity was cited as evidence that agentic AI is already being used to automate support tasks for cyberattacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcesecurity.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.