Palo Alto Networks Unit 42 warned that frontier and commercially available agentic AI is shifting offensive capability toward attackers, enabling lower-skilled actors to conduct vulnerability discovery, reverse engineering, malware development, social engineering, and other attack-chain activities at machine speed. In an investigation involving a customer, Unit 42 said an attacker reportedly used an agentic framework to exploit 50 applications and other enterprise weaknesses in under 10 hours, including exploitation, privilege escalation, and data theft.
Unit 42 said AI is already supporting malware creation, task delegation, ransomware negotiations, and reconnaissance, while making attribution more difficult. It identified identity compromise, software supply-chain exposure, and nation-state discovery of enterprise weaknesses as key risks, and urged organizations to adopt zero-trust controls, continuously train employees, govern internal AI use, and build adaptable security strategies for agentic AI.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported an AI-enabled operation that identified and exploited vulnerabilities, escalated privileges, and stole data within 10 hours, work it said would normally take a penetration-testing team about two weeks.
Unit 42 began investigating an attack against one of its customers in which an attacker reportedly used an agentic framework to exploit 50 applications and other enterprise weaknesses in under 10 hours.
During three weeks of internal testing with AI penetration-testing models, Unit 42 said it completed work comparable to one or two years of conventional penetration testing and uncovered dozens of vulnerabilities across customer environments.
Five months after its estimate, Unit 42 reported seeing early waves of the anticipated AI-enabled threat activity in the wild.
Through its Project Glasswing evaluations, Unit 42 estimated that the assessed AI capabilities could become available to attackers within one year.
Palo Alto Networks Unit 42 launched Frontier AI Defense, combining threat intelligence, threat telemetry, and frontier AI models for enterprise security use cases.
Anthropic formed Project Glasswing with Palo Alto Networks and other technology companies to identify and remediate security defects using Anthropic's Mythos model.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.