
In September 2025, Anthropic revealed that a government-backed attacker utilized an AI coding tool for an automated cyber spying operation targeting 30 global victims. The AI independently managed 80-90% of the attack by doing reconnaissance, creating exploit code, and rapidly attempting to move across the network.
While concerning, a more critical danger for security teams is an attacker who bypasses the entire attack sequence by compromising an AI agent already within your network. This agent would already possess the necessary access, permissions, and a legitimate reason to operate freely across your systems.
The conventional attack framework assumes attackers must obtain access progressively. This framework, created by Lockheed Martin in 2011, outlines how attackers progress from initial entry to achieving their final goal. It has shaped how security teams approach threat detection.
The rationale is straightforward: attackers must complete a series of actions, and defenders can interrupt the process at any moment. Each action an attacker must take presents another chance for discovery.
Each stage offers detection possibilities: endpoint security might identify the initial malicious software, network monitoring might reveal unusual movement within the network, identity systems might detect elevated privileges, and SIEM correlations might combine unusual activities across systems. With each additional action, attackers are more likely to be detected.
This explains why sophisticated attackers such as LUCR-3 and APT29 focus on stealth, remaining undetected for weeks while exploiting legitimate resources and mimicking normal activity. Despite their efforts, they leave behind traces: atypical login locations, unusual access patterns, and subtle deviations from standard behavior. These traces are what modern detection systems are designed to find.
However, AI agents don’t really adhere to this pattern.
AI agents function very differently than human users. They interact across systems, transfer information between applications, and operate continuously. If an attacker gains control, they bypass the entire kill chain – the agent embodies the threat itself.
Consider the typical level of access granted to an AI agent. Its activity history provides a complete overview of available data and its locations. It likely retrieves information from Salesforce, publishes to Slack, synchronizes with Google Drive, and updates ServiceNow as part of its regular operation. It was granted extensive permissions, often including administrator rights across various applications, and it routinely transfers data between systems to perform its tasks.
An attacker who compromises an agent gains immediate access to all of these capabilities. They acquire the map, the access privileges, the necessary permissions, and a valid rationale for moving data. The stages of the attack sequence that security teams have been developing defenses for? The agent effectively skips them.
The OpenClaw event showed us what this looks like in action:
About 12% of apps within its public marketplace were harmful. A critical Remote Code Execution (RCE) vulnerability enabled compromise with a single click. Over 21,000 instances were publicly accessible. More alarming, a compromised agent could access a range of sensitive information through its connections to Slack and Google Workspace, including messages, files, emails, and documents, with continuous memory across sessions.
The fundamental challenge is that current security measures are designed to identify abnormal activity. When an attack leverages an AI agent’s established workflow, everything seems normal. The agent accesses the same systems, moves the same data, and operates at the same times as usual.
This vulnerability is the detection gap that security teams face.
Defending against compromised AI agents begins with identifying the agents operating in your environment, their connections, and their permissions. Most organizations lack an inventory of AI agents interacting with their SaaS environment. This is the type of problem that Reco was designed to solve.
Reco’s Agentic AI Security identifies every AI agent, embedded AI feature, and third-party AI integration present within your SaaS ecosystem, including unauthorized AI tools connected without approval from IT.
Reco analyzes each agent’s connections to SaaS applications, its permissions, and its data access capabilities. Reco’s SaaS-to-SaaS visualization accurately shows how agents are integrated throughout your application ecosystem, uncovering harmful combinations where AI agents serve as a link between systems with MCP, OAuth, or API integrations, creating permission structures that no single application owner would authorize.
Reco determines which agents pose the greatest risk by evaluating their permission scope, access to multiple systems, and the sensitivity of the data they handle. Agents associated with emerging problems are automatically flagged. Reco then assists in optimizing access through identity and access governance, directly limiting what an attacker can achieve if an agent is compromised.
Reco’s threat detection engine analyzes the behavior of AI agents with the same identity-centric approach used for human identities, differentiating between standard automation and suspicious deviations in real time.
The conventional kill chain assumed that attackers had to overcome obstacles to gain access. AI agents invalidate that idea.
A single compromised agent grants an attacker legitimate access, a comprehensive view of the environment, extensive permissions, and built-in cover for data movement, without any actions that appear to be an intrusion.
Security teams that remain exclusively focused on detecting human attackers will overlook this type of threat. Attackers will leverage existing AI agent workflows, staying hidden in the background of normal operations.
It’s only a matter of time before an AI agent within your environment becomes a target. Visibility will determine whether you catch it early or discover it during incident response. Reco offers that visibility across your entire SaaS ecosystem in minutes.
Learn more here: Request a Demo: Get Started With Reco.
#attacker: #attacks #can’t #chain #cyber #defense #defenses #fails or ai #keep #kill #news #the #traditional — News
© Bulletproof Servers. All rights reserved.