Google iconGoogleSep 8, 2026 ~6 min source read

GTIG AI Threat Tracker: How Adversaries Moved From Prompting to Agentic, Automated Attacks

Google Threat Intelligence Group describes a shift in adversary tradecraft: attackers are combining agentic AI, AI-assisted coding abuse, and targeted strikes against AI assets to compress attack timelines and broaden impact.

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Share this story

Send the public story page.

Useful takeaways from this story.

Threat actors are explicitly targeting AI assets—model code, weights, API keys, and cloud compute—to enable espionage, extortion, and illicit compute, making these assets high-value targets.

Google’s layered defenses include model-level safeguards, proactive disruption of malicious projects/accounts, and an autonomous Google AI Threat Defense architecture to operationalize protections.

Adversaries are combining multiple AI capabilities rather than using models only as one-off tools. The observable shifts include:

  • Agentic AI and automation: Multi-agent frameworks autonomously manage scanning, resolve operational errors, and execute large-scale credential theft. Human-in-the-loop latency drops sharply as agents carry out iterative workflows.
  • Supply chain targeting: The proliferation of AI-assisted coding, open source AI resources (model context servers, model weights, inference engines, vector DBs), and faster development cycles created new attack surfaces. GTIG links AI-assisted coding practices to notable software supply chain compromises in 2025–early 2026.
  • Targeting AI assets: Adversaries seek proprietary models, source code, prompts, and API credentials. Motivations range across espionage, extortion, and theft of cloud compute to run unauthorized AI workloads.

GTIG's public findings describe several concrete patterns observed in 2026 telemetry and research:

  • A rapid mass credential-harvesting campaign that an agentic framework designed and executed within a six-hour window after initial cloud compromise.
  • UNC6780 leveraging multiple tactics to trick AI coding assistants and LLM security scanners so malicious code could enter open source software supply chains.
  • Attempts to download malicious open-source AI resources across enterprise environments in North America and Asia, and a reported case where an AI coding agent introduced a malicious dependency into a live cryptocurrency-related codebase.

Defender implications and recommended focus areas GTIG's analysis points to where defenders must prioritize effort:

  • Treat AI assets as high-value: Model weights, proprietary prompts, API keys, and high-performance cloud quotas require access controls, inventorying, and monitoring equivalent to other critical IP.
  • Harden development supply chains: Increase scrutiny of third-party packages and dependencies, especially in AI-focused repositories and components such as MCP servers and inference tooling.
  • Monitor for account misuse and illicit compute: Watch for credential theft, purchased compromised AI platform accounts, and unexpected cloud workloads that could indicate LLMJacking or compute theft.

Adversaries are moving beyond one-off prompting to coordinated, agentic, and automated operations that exploit the AI software ecosystem and directly target AI assets. Defenders need inventory, controls, and detection tuned for AI-specific risks and must consider operational changes in development pipelines and cloud environments to reduce exposure.

More context around this story.

A.I. Is No Longer Just a 'Next Word Predictor'
Realclearpolitics iconRealclearpoliticsSep 11, 2026

A.I. Is No Longer Just a 'Next Word Predictor'

For months, news that artificial intelligence agents from OpenAI had gone rogue and attacked another company's systems (as well as OpenAI's own systems) has dripped out and brought harrowing details into focus. The public is struggling to catch up: What are these secret A.I. systems? What are these "swarms" capable of,

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app