The 10-hour hack started when the (human) bad guy deployed an AI agent to do reconnaissance to figure out how to breach the company. The hacker essentially launched a massive internet scan that hunted for a way into the company’s network. It ultimately found and exploited a public API endpoint, which is essentially a door that companies expose to the open internet so outside software can talk to their systems.
That’s something “AI is pretty dang good at,” Piazza said, because “devices on the internet are being scanned all of the time, and so reconnaissance is not something you can really prevent.”
Once the hacker got into the company’s system, it deployed an agent to do internal recon to figure out what systems and software were running inside the network. In this case, the company’s coding pipeline and code repositories were identified as targets.
“You get a lot when you’re scanning inside of a network,” Piazza said. “You’re effectively trusted now because you’re inside the firewall. And they get a lot more details, and they can figure out what are the interesting systems they may want to go after from there.”
Sub-agents then went through code repositories and extracted credentials like passwords and tokens that developers had left, written directly into the company’s software. Piazza said too many businesses aren’t diligent enough about locking down their logins and credentials, a practice that “stops a lot of stupid badness on the internet.”
The agents then used those stolen logins to break into the system the company uses to build and deploy its software — and from there grabbed the keys to its cloud accounts, letting the hackers run their operation through the company’s own AI tools. That’s a technique known as “living off the land,” in which hackers use the victim’s own software to do harm, making it harder to detect.
That hacking strategy could become more common since AI systems are getting more access to sensitive company data, Piazza said: “We’re starting to see [that] bad guys are getting access to that AI compute.”
The attacker — or its agents — ultimately demanded a ransom, but “this is one of those good news stories where we identified it and got them out before they were fully successful,” he said. An AI agent still left behind an 80-page, technical report detailing the company’s vulnerabilities.
Click Here For The Original Source.
