Cato Networks reported that an AI-enabled attack stack autonomously compromised a simulated enterprise Active Directory environment from an external foothold to Domain Administrator privileges, with the fastest run completing in about 40 minutes from a single high-level prompt. In six lab scenarios, the system reportedly carried out reconnaissance, exploitation, internal discovery, privilege escalation, lateral movement, and exfiltration while requiring minimal human direction, showing how agentic workflows can execute full attack chains rather than isolated tasks.
Reporting on the research said the decisive factor was not the frontier model alone but the surrounding "harness"—the orchestration layer that constrains the model, connects it to tools, and supplies operational context. Cato paired OpenAI models including GPT-5.5 and GPT-5.5-Cyber with MCP-enabled tooling and found that this stack drove performance more than the base model itself, reinforcing a broader industry view that harness engineering, benchmarking, and human oversight are becoming central to both AI-powered cyber defense and the automation of known offensive techniques.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Cato Networks reported a controlled enterprise lab study in which an agentic attack stack autonomously executed an end-to-end compromise of an Active Directory environment. In its fastest successful run, the system reportedly progressed from external access to Domain Administrator privileges in about 40 minutes from a single high-level prompt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
reversinglabs.com
Open sourceinfosecurity-magazine.com
Open sourcecatonetworks.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.