Google GTIG: threat actors now run agentic AI attacks, harvesting credentials in under 6 hours

ChuckDBrooks · x · 2026-09-08

Google's Threat Intelligence Group reports adversaries have shifted from basic prompting to agentic AI workflows. In Q2 2026, one actor compromised a cloud resource and executed an agent-enabled mass credential harvesting campaign in under six hours; UNC6780 tricked AI coding assistants and LLM security scanners in OSS supply chain compromises.

Key trends:

Enterprise AI assets—from weights to compute quotas—are now high-value targets for espionage, extortion, and resource theft.

Original post →

More from coding & agent

coding & agent channel →