
What happened
Palo Alto Networks' Leeor Piazza said an AI agent scanned the internet, found a public API endpoint, then moved inside a European IT and software company's network.
Why it matters
The agents stole developer credentials and cloud keys, using the victim's own software — a 'living off the land' technique that is harder to detect, Piazza said.
What to watch
Piazza said such attacks are likely to grow as AI systems get access to sensitive company data. The test is whether firms lock down logins, which he said stops 'a lot of stupid badness.'
WHO IT HITSSecurity teams at software and IT companies are the ones who would need to act on this, since the hack turned on unsecured credentials left inside code repositories and on a public API endpoint.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Palo Alto Networks walked Semafor through a hack that played out over roughly 10 hours, starting with a human attacker who handed reconnaissance to an AI agent. That agent ran a broad internet scan and found a public API endpoint — an opening companies leave so outside software can talk to their systems. Piazza's point is that this kind of scanning is constant and hard to prevent, which is what made the entry point attractive.
Once inside, the intruder switched to internal reconnaissance, mapping what systems and software were running. The coding pipeline and code repositories stood out as targets. Sub-agents then combed those repositories and pulled out credentials — passwords and tokens developers had left written directly into the company's software. Those logins opened the system the company uses to build and deploy software, and from there the attackers took the keys to its cloud accounts, running the operation through the victim's own AI tools. Piazza described this as 'living off the land,' which makes the activity harder to detect.
His reading is that this playbook could spread, because AI systems are getting more access to sensitive company data. For security teams, the practical question is whether credentials are properly locked down; Piazza framed that discipline as what keeps a lot of low-grade attacks out. The outcome here hinged on the intrusion being spotted in time, and it was — the attacker demanded a ransom but was ejected before succeeding, though an AI agent left behind an 80-page technical report on the company's vulnerabilities.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Calls to moderate frontier AI development have surfaced a financial dilemma alongside the safety debate, since…

At the Pro-Human Assembly in Washington, Bernie Sanders and Steve Bannon both called for tighter AI limits, wh…

Mozilla and Mistral launched Firefox Smart Window (beta), an AI assistant that helps with complex searches, re…

TypeSafe AI introduced Jev, a classification-only model that scores developer-defined options instead of gener…

Cognition's Devin began offering macOS inside its hosted virtual environment on September 15, 2026, joining th…

Anthropic's Chris Cronbaugh told Sleuthcon that after a prepaid account sent over 100,000 API requests a day t…
