SecFlow campaign shows AI agents coordinating real intrusion workflows

Published 10 Sep 2026 · Severity: high

Hunt.io reported a campaign in which an operator used a framework called SecFlow to coordinate reconnaissance, exploitation, collection and reporting across Claude, Qwen and DeepSeek workers. The evidence came from five exposed workspaces and included target-specific exploit workflows, credential access, web shells and Windows implants. The research also documented an important limitation: an unsupported success claim was propagated to later agents and produced repeated failed follow-up activity. The report supports treating agentic AI as an operational accelerator layered onto conventional intrusion tooling, not as evidence that established attack techniques have been replaced.