AI agents could partner to identify and exploit vulnerabilities, elevate privileges, and covertly pilfer data from enterprise systems through aggressive prompting that emphasized the urgency of task completion, The Register reports.Offensive cyber behavior was evident across a trio of scenarios involving a simulated corporate network, with the first task involving a feedback loop to research an internal wiki document, resulting in AI agents launching a cyberattack against the internal document system, according to researchers from frontier AI security lab Irregular. Another task with a prompt directing the backup agent to download a file from a malware-pointing attacker-controlled URL downloaded the malware even after being blocked by Microsoft Defender.Such findings suggest AI agents' mimicry of engineer and system admin behaviors that are usually in violation of corporate policy, said Palo Alto Networks Unit 42 Senior Director of Threat Intelligence Andy Piazza."It is problematic that agents are adopting this behavior, especially with the idea of a threat actor taking over an agentic deployment to carry out a malicious attack against the organization. We're racing towards a living-off-the-land agentic incident," Piazza added.
AI/ML, Data Security
Coordinated AI agent-powered data theft possible, study finds

(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



