Mandiant's AI risk report records an agent that ran up about $50,000 in cloud charges with no attacker involved
The Mandiant AI Risk and Resilience Report 2026, produced with Google Threat Intelligence Group, says enterprise AI “transitioned from human-guided advisory tools to autonomous, agentic systems that orchestrate complex workflows and execute end-to-end operations,” and that “as attack vectors evolve from direct chat prompts to complex indirect prompt injection and targeted AI supply chain compromise, traditional security boundaries blur.” It records a global enterprise financial services provider that saw a “sudden ~$50,000 cloud-billing spike” when an agent entered an unconstrained reasoning loop and generated more than 15,000 high-frequency API calls in under an hour, and an AI-enabled source code review harness that “discovered over 100 true-positive critical vulnerabilities in just two days” during an incident response investigation. It repeats that in May, GTIG “disclosed the first publicly confirmed case of a cybercriminal using an AI-developed zero-day exploit to plan a mass exploitation campaign.”
Google says a PRC-nexus actor runs open-weight models on victim compute to escape API monitoring, and that AI models and prompts are now extortion targets
The same report says GTIG observed suspected UNC6508 activity “compromising cloud environments to deploy local LLM infrastructure”: “By using a local, open-weight model deployed in compromised infrastructure, UNC6508 is able to avoid commercial AI API monitoring, while co-opting victim compute resources,” against academic, medical and military research institutions in North America. Mandiant separately investigated “multiple data theft extortion operations in which threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research,” affecting technology, healthcare and media and entertainment companies in North America and Europe. Google also says it now sees coordinated distillation campaigns against its own models “on a regular basis, some exceeding 100 million prompts.”
Google records an attacker planning, building and running a mass credential-harvesting campaign with an autonomous multi-agent framework in under six hours
In its September AI Threat Tracker, Mandiant reports a suspected financially motivated actor compromising an organisation's cloud infrastructure to deploy an autonomous, multi-agent attack framework: “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” using preconfigured markdown instruction sets as operational playbooks and compromising thousands of third-party credentials. A separate reconnaissance framework ran a production dashboard managing “over 23,800 harvested secrets in real time, including API keys for cloud and AI services.” Google adds that it “has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild.”
Google says its agentic vulnerability-discovery system found 100-plus critical flaws in two days
Google's Mandiant/Threat Intelligence Group described an Agentic Vulnerability Discovery Harness (AVDH) that it says found more than 100 verified high-severity vulnerabilities in two days while examining stolen corporate repositories, and that over roughly ten months across tens of millions of lines of code produced tens of thousands of findings and 12 assigned CVEs, with a further dozen in active disclosure. Google published the system's multi-agent pipeline and said every confirmed finding is still reproduced and validated by a human analyst, with proof-of-concept code, before it counts.
Mandiant records a 1,444% rise in detected malicious open-source packages and names the crews behind two campaigns
Citing Open Source Security Foundation figures, Mandiant says the number of malicious open-source packages identified rose 1,444% from 2024 to 2025. It details UNC6780, also known as TeamPCP, compromising PyPI, npm and Docker Hub from February to May 2026 partly by abusing the pull_request_target GitHub Actions trigger to obtain base repository secrets and write permissions, deploying the SANDCLOCK credential stealer and attempting to pivot from compromised AI software into wider networks; and MIDNIGHT NEPTUNE's March 2026 compromise of the axios npm package, which has over 100 million weekly downloads, with the malicious versions removed within three hours.