Security researchers and practitioners are increasingly highlighting that agentic AI—systems that plan multi-step workflows and execute real-world actions via tools, plugins, and APIs—introduces a materially different risk profile than traditional LLM chat applications. Compared with conventional LLM use (text generation, Q&A, and RAG), agentic systems can autonomously take actions that cascade across connected services (e.g., sending emails, modifying records, calling external APIs), driving the need for updated threat modeling and control frameworks aligned to emerging guidance such as an Agentic AI Top 10 alongside the OWASP LLM Top 10.
A concrete example of this weaponization is ScamAgent, an autonomous multi-turn framework developed at Rutgers University that demonstrates fully automated scam calls using LLMs plus real-time text-to-speech. Reported design elements include a central orchestrator to manage conversational state, goal decomposition to break malicious objectives into benign-seeming steps, and roleplay/deception techniques to evade single-turn safety guardrails in models such as GPT-4 and LLaMA3-70B; the system also uses contextual memory to adapt tactics over time. The work underscores that defenses must account for multi-step, stateful interactions (not just single prompts), and that agent capabilities (memory, tool access, persona/impersonation, and action execution) are key control points for reducing autonomous social-engineering risk.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A March 2026 analysis contrasted traditional LLM applications with agentic AI systems, arguing that autonomous planning, tool use, and API-driven actions create broader and more cascading security risks. It concluded that these differences require a new security paradigm beyond the traditional OWASP LLM Top 10 framing.
The report warned that ScamAgent's use of goal decomposition and roleplay framing can bypass single-turn moderation and typical AI safety guardrails. Researchers recommended continuous intent-aware monitoring, sequence classifiers, and tighter memory-retention limits to defend against autonomous generative threats.
In evaluations across five fraud scenarios, researchers found the agentic approach reduced model refusal rates compared with direct malicious prompting. The report said models including GPT-4, Claude 3.7, and LLaMA3-70B were more likely to complete harmful dialogues under the multi-turn framework, with LLaMA3-70B performing especially strongly in a job identity fraud simulation.
Rutgers University researcher Sanket Badhe created ScamAgent, a multi-turn autonomous AI framework designed to demonstrate how large language models can be weaponized for fully automated scam calls. The system uses goal-driven planning, contextual memory, and real-time text-to-speech to sustain realistic social-engineering conversations.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.