VECTOR WIREAI INTELLIGENCE
NVDA$1,847+3.2%MSFT$512+1.1%GOOGL$199-0.4%META$728+2.7%AMD$184-1.2%TSM$212+0.6%PLTR$98+4.1%AI IDX4,821+1.9%
PKT
SEEDRefresh Models Deals Regulatory Sources

Agentic AI Opens a Two-Sided Attack Surface

Cisco Talos documents adversary AI integration in live intrusions while an AI coding agent nearly installs malware, as NCSC issues interim agentic AI…

Vector Wire — AI-assisted editorial illustration

Cisco Talos has documented a Chinese-speaking cybercrime group integrating AI-driven tooling into live intrusions2. An AI coding agent nearly tricked a developer into installing malware3,4. And the UK's National Cyber Security Centre published interim guidance urging stronger controls for agentic AI systems1. ANALYSIS The convergence of an adversary integrating AI into real-world attacks, an AI coding agent nearly poisoning a developer's environment, and a national cyber agency issuing interim guidance suggests the agentic attack surface is expanding faster than defenses.

Why it matters

Agentic AI is no longer a lab curiosity. Cisco Talos has now documented a Chinese-speaking cybercrime group, tracked as UAT-10147, that integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persistence workflows during real-world intrusions targeting Windows and Linux web servers globally. Separately, an engineer at the international software firm Softjourn nearly installed a malicious package after an AI agent recommended a library with a completely plausible name, similar to already known solutions. The UK's National Cyber Security Centre (NCSC) published interim practical advice urging organizations to use sandboxing, human oversight, and tightly controlled access to limit the impact of unintended or malicious agentic AI activity. Taken together, these events show that agentic AI is creating risk on both sides of the security perimeter — empowering attackers and undermining defenders — at the same time.

The big picture

UAT-10147 targeted organizations in government, education, media, technology, and gaming sectors, leveraging publicly disclosed vulnerabilities to gain initial access at scale. What distinguishes the campaign is the depth of AI integration: Talos observed AI-generated operational playbooks, exploit automation scripts, and troubleshooting logic supporting real-world intrusions. The group employed open-source offensive frameworks including Metasploit, ysoserial, PentestGPT, and DeepAudit alongside multiple privilege escalation exploits to automate intrusion operations and establish persistence. Talos assessed that integrating AI-generated exploitation guidance, automation, and validation workflows enables threat actors to scale complex attacks more efficiently while reducing the expertise traditionally required for advanced post-compromise operations.

ANALYSIS That assessment points to a structural shift: agentic AI lowers the skill floor for sophisticated attacks, meaning a broader pool of adversaries can now execute campaigns that previously demanded deep technical expertise.

On the defensive side, the Softjourn incident illustrates a different but related failure mode. Sergiy Fitsak, managing director and CTO of Softjourn, told The Register that "attackers have learned to use hallucinations of AI models". The tactic, which security researchers call "slopsquatting," works because AI models sometimes invent package names that sound plausible but don't exist; attackers then register real malicious packages under those invented names, betting that a developer under deadline pressure will install first and check later. The malicious code in the Softjourn case could have given criminals a backdoor into the company's systems and the ability to steal data. The engineer caught the threat only because Softjourn enforces a strict policy of mandatory verification of any software advice from AI — the developer reviewed the package's source code on GitHub and noticed minimal downloads and a creation date of just a few days ago.

Between the lines

The NCSC's guidance recommended that organizations first assess how much autonomy a system actually needs and identify what could go wrong before deployment. The agency said organizations should threat-model the agent's prompts, tools, networks, and accessible services, then use the results to determine which additional controls are required. Critically, the NCSC warned that organizations should not rely solely on safeguards built into an underlying model or agent framework.

ANALYSIS That warning resonates directly with the Softjourn case: the AI agent's own output was the vector, and no built-in guardrail flagged the hallucinated package name. It also maps onto the UAT-10147 campaign, where the adversary's AI tooling operated within standard offensive frameworks — meaning perimeter defenses tuned to known signatures would not necessarily detect AI-augmented exploitation logic.

The NCSC noted that its advice follows several incidents involving AI models carrying out unsanctioned or unintended activity, and that formal guidance is still being developed. The fact that a national cyber agency is issuing interim blog-post-level guidance — explicitly flagging it as a stopgap before formal standards arrive — signals that the policy apparatus is trailing the operational reality.

What's next

The NCSC said formal guidance will eventually supersede the interim blog post. Until that guidance materializes, organizations face a gap: agentic AI is being deployed in production environments while the controls governing it remain advisory and ad hoc. The Softjourn case shows that a simple verification policy — checking download counts and reviewing source code — can stop a slopsquatting attack, but that policy existed because the company anticipated the risk. The UAT-10147 campaign shows that adversaries are not waiting for defenders to catch up. The two-sided attack surface is open, and the window between interim advice and enforceable standards is where the damage will accumulate.