Threat actors are giving AI agents a bigger role in cyberattacks

Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are increasingly being used to automate parts of cyberattacks, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. GTIG also observed threat actors experimenting with Gemini, Claude, and Codex to build offensive frameworks and exploit chains, while highlighting campaigns involving Recon, Shai-Hulud, and large-scale credential theft. #GoogleThreatIntelligenceGroup #Gemini #Claude #Codex #Recon #ShaiHulud

Keypoints

  • AI agents are reducing the need for human input in attack workflows.
  • A threat actor used an AI chatbot to steal thousands of credentials in less than six hours.
  • Recon was exposed as an automated framework for reconnaissance and credential management.
  • PRC-nexus actors tested AI tools to build penetration testing and exploitation pipelines.
  • GTIG says fully autonomous attack pipelines have not yet been seen in the wild.

Read More: https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/