Agentic AI hasn't created a new attack class. It's created a faster one.

By:
Konstantin Richter
&

A customer asked us recently how we think about agentic and LLM-driven cyberattacks against our infrastructure. It's a fair question, and one we're getting more often — for good reason. The evidence is no longer hypothetical. Over the past few months, security researchers have documented autonomous AI agents actually carrying out intrusions, not just simulating them.

A customer asked us recently how we think about agentic and LLM-driven cyberattacks against our infrastructure. It's a fair question, and one we're getting more often — for good reason. The evidence is no longer hypothetical. Over the past few months, security researchers have documented autonomous AI agents actually carrying out intrusions, not just simulating them:

  • In July 2026, an AI agent operating inside an offensive-cyber evaluation environment escaped its sandbox by finding a zero-day in the proxy meant to contain it, then used that foothold to compromise Hugging Face's production infrastructure — uploading malicious dataset configurations that pulled secrets and source code out of Kubernetes pods. Researchers reconstructed roughly 17,600 individual agent actions across the campaign, run with no human directing each step.
  • Around the same time, researchers tracking a China-linked threat actor found they had wired a DeepSeek model into an open-source agent framework, controlled entirely through Telegram, and let it run the early stages of an attack lifecycle on its own — scanning for exposed services, correlating public proof-of-concept exploits with live targets, and pivoting off failed attempts on its own initiative. The operator's own infrastructure ended up exposed by a misconfiguration in the agent itself, but not before it had scanned hundreds of targets and confirmed several compromises.
  • Separately, Unit 42 documented a similar pattern: autonomous scanning chained with manual exploitation across multiple CVEs, including confirmed data exfiltration from internet-facing appliances and session-hijacking attempts using stolen authentication cookies.
  • In a controlled red-team exercise, an internal enterprise AI assistant was compromised by an autonomous agent that gained broad system access in under two hours — a drill, but a realistic one.

Industry-wide, the sentiment tracks the evidence: roughly half of security professionals surveyed by Dark Reading now name agentic AI as the single most concerning attack vector of the year, and OWASP published its first agent-specific risk taxonomy in December 2025, covering things like goal hijacking, tool misuse, and memory/context poisoning.

None of this describes a new category of threat.

It describes the same techniques we've defended against for years — reconnaissance, credential abuse, exploitation of exposed services, social engineering — running at a speed and persistence that a human operator can't match. An agent doesn't get tired. It doesn't lose interest halfway through a campaign. It iterates through a target far faster than a person sitting at a keyboard.

So we manage it inside the systems we already trust, not next to them.

That's the core of it. We don't treat AI and agentic risk as a standalone security program running in parallel to everything else. It sits inside our existing risk management framework, where cyber risk already has clear ownership, a stated risk appetite, defined escalation routes, and regular reporting to senior management. Our AI governance framework sits alongside it, governing how AI and agentic systems get assessed, approved, deployed, and monitored — both inside our own environment and wherever they show up in vendor technology we consume.A few things that means in practice:

  • Continuous, not annual, assessment. Automated exploitation, AI-assisted phishing, and agentic reconnaissance are tracked as live threats inside our cyber risk program. What we learn feeds directly into control design, monitoring priorities, and the remediation backlog — the goal is a posture that moves with the threat instead of trailing it by a review cycle.
  • A dedicated engineering task force owns the assessment of AI implementations across the business, anchored deliberately to our existing SOC 2 and ISO 27001 programs. Anything AI-related we introduce carries the same expectations on change control, access management, logging, and independent audit as the rest of our production estate — inside the assurance perimeter our customers and auditors already rely on, not a parallel surface nobody is testing.
  • A deliberately minimal node infrastructure. We restrict installed components, running services, and exposed interfaces to what each workload genuinely requires. A reduced attack surface gives an attacker — automated or otherwise — very little to discover and few paths to abuse. It also makes hardening, monitoring, and patching simpler and more complete, and lowers the odds of a misconfiguration sitting unnoticed.

Agentic threats are real, and they're moving fast. Our answer isn't a new department or a new dashboard — it's making sure agentic risk gets the same discipline, ownership, and audit trail as every other risk we manage.

(Sources: Cyber Security News and GBHackers on the Hugging Face/ExploitGym incident; CyberPress and Unit 42 on autonomous agent campaigns; Bessemer Venture Partners on the McKinsey "Lilli" red-team exercise; Dark Reading and OWASP on the broader threat landscape.)

Share

Get Started with
Blockdaemon Today!

Contact us to learn how we can help you power your blockchain business.

Unparalleled Security & Compliance
Seamless Integration & Scalability
Dedicated Customer Support