Google GTIG: threat actors now run agentic AI attacks, harvesting credentials in under 6 hours
ChuckDBrooks · x · 2026-09-08
Google's Threat Intelligence Group reports adversaries have shifted from basic prompting to agentic AI workflows. In Q2 2026, one actor compromised a cloud resource and executed an agent-enabled mass credential harvesting campaign in under six hours; UNC6780 tricked AI coding assistants and LLM security scanners in OSS supply chain compromises.
Key trends:
- Expanding supply chain risk: AI-assisted coding makes developers, coding assistants, and LLM security scanners targets
- Attackers increasingly steal proprietary model weights, source code, and API credentials, and hijack victim cloud environments to run unauthorized AI workloads
- Human-in-the-loop latency is shrinking, compressing defenders' response windows
Enterprise AI assets—from weights to compute quotas—are now high-value targets for espionage, extortion, and resource theft.
More from coding & agent
- ML syntax highlighter matches Shiki accuracy with the model inlined in the bundle — shuding · 2026-09-08
- gpu-lexer author: trained on 50+ languages, model is ~70% of the 27.5KB bundle — shuding · 2026-09-08
- gpu-lexer is fast via WebGPU and off-main-thread, but not yet a replacement, author says — shuding · 2026-09-08
- gpu-lexer: Vercel's 27.5KB WebGPU model does language-agnostic syntax highlighting in the browser — shuding · 2026-09-08
- Dev finds 129 Claude-created worktrees piling up in his repo — alec_helbling · 2026-09-08
- Deemos Launches Hyper3D MCP to Generate 3D Models Directly Inside Codex — sidahuj · 2026-09-08