AI agents are increasingly being used to automate parts of cyberattacks, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. GTIG also observed threat actors experimenting with Gemini, Claude, and Codex to build offensive frameworks and exploit chains, while highlighting campaigns involving Recon, Shai-Hulud, and large-scale credential theft. #GoogleThreatIntelligenceGroup #Gemini #Claude #Codex #Recon #ShaiHulud
Keypoints
- AI agents are reducing the need for human input in attack workflows.
- A threat actor used an AI chatbot to steal thousands of credentials in less than six hours.
- Recon was exposed as an automated framework for reconnaissance and credential management.
- PRC-nexus actors tested AI tools to build penetration testing and exploitation pipelines.
- GTIG says fully autonomous attack pipelines have not yet been seen in the wild.
Read More: https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/