As cited
Copy frozen at (site build).
threat intel
GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI
Google Threat Intelligence Group released a Q2 2026 report documenting how threat actors have evolved from basic large language model (LLM) prompting to autonomous artificial intelligence (AI) agents and agentic automation. Financially motivated and state-sponsored groups now leverage AI across attack lifecycles, from reconnaissance and malware development to post-exploitation, with some completing credential harvesting campaigns in under six hours. Attackers increasingly target proprietary AI models and cloud compute resources, while exploiting open-source software supply chains using AI-assisted coding tools.
Why it matters: Practitioners must secure AI accounts, cloud infrastructure, and proprietary models against compromised developer credentials and account theft; threat actors now move from initial compromise to large-scale credential harvesting with minimal human intervention, requiring real-time detection and response capabilities. Organizations using open-source software face elevated risk from AI-discovered vulnerabilities and supply chain poisoning. Defenders need to monitor for agentic attack patterns, protect application programming interface (API) keys in developer configurations, and implement controls on cloud compute quotas to prevent unauthorized AI workload deployment.
- Source published
- First seen by Cybersecurity Tracker