GTIG tracks adversarial AI shift from prompting to agent-enabled operations
Published 11 Sep 2026 · Severity: high
Google Threat Intelligence Group reported on 8 September 2026 that observed adversaries are moving from basic prompting towards agentic workflows and AI-enabled automation. In one Q2 case, actors compromised a cloud resource and then planned, built and ran an agent-enabled mass credential-harvesting campaign in under six hours. The report also documents attacks on AI coding assistants, MCP integrations, CI/CD identities, model assets and cloud compute. Important limit: GTIG says it has not yet observed threat actors deploying fully autonomous attack pipelines against targets in the wild.