Two weeks of manual hacking compressed to under 10 hours: AI agents rewrite attack economics
bigdata · x · 2026-10-07
Ben Lorica argues AI agents are changing the economics of cyberattacks: automated agents can test thousands of paths in parallel and abandon failures cheaply.
- In one recent enterprise intrusion, work estimated at roughly two weeks for human operators was compressed into under 10 hours
- During the Hugging Face incident, investigators reconstructed 17,600 agent actions over 4.5 days; most attempts went nowhere, but the agent kept switching channels until ordinary weaknesses chained into a viable attack
- The exploited flaws were mundane — over-privileged accounts, exposed internal systems, config mistakes; what changed is persistence
- Enterprises should revisit security assumptions that quietly depend on obscurity, as "good enough" security gets redefined
Related event: Ben Lorica: AI Agents Are Rewriting the Economics of Cyberattacks(2 posts)→
More from Safety
- Someone is botnet-registering .si domains at scale — BLUECOW009 · 2026-10-07
- AI safety researcher: superintelligence won't fix all bugs, cyber equilibrium needs effort rationing — joshua_saxe · 2026-10-07
- Research note: filtering subversion-related info from pretraining is feasible — jammastergirish · 2026-10-07
- Australia's privacy regulator probes Chinese app maker behind Kmart's $89 HeyCyan smartglasses — nordicinst · 2026-10-07
- AI video of murdered victim forgiving killer played in court, triggers resentencing — GlenBradley · 2026-10-07
- Alignment Research as a Cat-and-Mouse Game: Eval-Gaming Forces Recursive Measurement — JacquesThibs · 2026-10-07