AIToday
Large Language ModelsAI Safety & AlignmentSemafor TechPublished: Sep 17, 2026, 01:00 JST

Palo Alto Networks details 10-hour AI agent hack

Palo Alto Networks details 10-hour AI agent hack

3 Key Points

  1. What happened

    Palo Alto Networks' Leeor Piazza said an AI agent scanned the internet, found a public API endpoint, then moved inside a European IT and software company's network.

  2. Why it matters

    The agents stole developer credentials and cloud keys, using the victim's own software — a 'living off the land' technique that is harder to detect, Piazza said.

  3. What to watch

    Piazza said such attacks are likely to grow as AI systems get access to sensitive company data. The test is whether firms lock down logins, which he said stops 'a lot of stupid badness.'

WHO IT HITSSecurity teams at software and IT companies are the ones who would need to act on this, since the hack turned on unsecured credentials left inside code repositories and on a public API endpoint.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

Palo Alto Networks walked Semafor through a hack that played out over roughly 10 hours, starting with a human attacker who handed reconnaissance to an AI agent. That agent ran a broad internet scan and found a public API endpoint — an opening companies leave so outside software can talk to their systems. Piazza's point is that this kind of scanning is constant and hard to prevent, which is what made the entry point attractive.

Once inside, the intruder switched to internal reconnaissance, mapping what systems and software were running. The coding pipeline and code repositories stood out as targets. Sub-agents then combed those repositories and pulled out credentials — passwords and tokens developers had left written directly into the company's software. Those logins opened the system the company uses to build and deploy software, and from there the attackers took the keys to its cloud accounts, running the operation through the victim's own AI tools. Piazza described this as 'living off the land,' which makes the activity harder to detect.

His reading is that this playbook could spread, because AI systems are getting more access to sensitive company data. For security teams, the practical question is whether credentials are properly locked down; Piazza framed that discipline as what keeps a lot of low-grade attacks out. The outcome here hinged on the intrusion being spotted in time, and it was — the attacker demanded a ransom but was ejected before succeeding, though an AI agent left behind an 80-page technical report on the company's vulnerabilities.

FAQ
How did the AI agent get into the company?
It ran a massive internet scan, found a public API endpoint — a door companies expose so outside software can reach their systems — and exploited it to get inside the network.
What did the attacker take?
Sub-agents pulled passwords and tokens developers had written directly into the company's software, then used those to grab the keys to its cloud accounts.
Was the ransom paid?
No. Piazza said the attacker demanded a ransom, but the company identified the intrusion and got the hackers out before they were fully successful.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Mozilla's Firefox Smart Window beta runs on Mistral modelsTHE DECODER · 1h ago
  • TypeSafe AI's Jev skips text, scores options in 70msTHE DECODER · 1h ago
  • Devin adds hosted macOS so agents build Apple apps without a MacPublickey · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleOpenAI backs FRONTIER Act as Sanders, Bannon demand AI brakes