<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1" -->

---
title: AI agents help compress ransomware intrusion to under 10...
description: Palo Alto Networks&#x27; Unit 42 documented a ransomware intrusion where AI agents compressed what would normally take human operators about two weeks into under 10...
canonical: https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs | daily.dev
og:description: Palo Alto Networks&#x27; Unit 42 documented a ransomware intrusion where AI agents compressed what would normally take human operators about two weeks into under 10...
og:url: https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1
og:image: https://api.daily.dev/og/posts/rt3TWzBf1.png
og:image:alt: AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 0 upvotes · 0 comments

## Summary

Palo Alto Networks' Unit 42 documented a ransomware intrusion where AI agents compressed what would normally take human operators about two weeks into under 10 hours, spanning more than 50 MITRE ATT&CK techniques. The attacker entered via a public-facing API, used automated recon agents to map microservices, mined source-code repositories for exposed credentials, breached a secrets-management system, exfiltrated cloud access keys, and attempted to plant Terraform backdoors that existing branch protections blocked. Analysts describe this as human-directed intrusion with AI orchestrating tactical work rather than fully autonomous attack, and warn that faster attack cycles demand shorter detection-to-containment windows, short-lived credentials, cross-system telemetry correlation, and attention to 'transitive authority' where access in one system enables privileged action in another.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4217976/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos.html>

## Questions this post answers

### How much faster was the AI-assisted ransomware attack compared to a typical human-led intrusion?

The attack was completed in under 10 hours, compared to an estimated two weeks for similar work by human operators, according to Palo Alto Networks' Unit 42 team. The intrusion involved more than 50 techniques mapped to the MITRE ATT&CK framework, with AI agents interpreting results and adapting subsequent steps during the attack.

_Security teams tightening detection-to-containment windows against faster attacks can track this research on daily.dev._

### What is transitive authority in cloud and identity security?

Transitive authority describes a situation where access in one system enables a more privileged action in another, even without direct permissions. For example, a repository account without cloud administrator privileges could alter a workflow that assumes a more powerful cloud role, so entitlement reviews should assess what an identity can cause other systems to do, not just what it can access directly.

_Teams reviewing entitlements across dev and cloud environments follow analyses like this on daily.dev._

### How did attackers exfiltrate cloud access keys in the AI-assisted ransomware intrusion analyzed by Unit 42?

Attackers hijacked an enterprise code application through custom workflows to exfiltrate cloud access keys, after AI agents searched source-code repositories for exposed credentials and used those to breach a secrets-management system and obtain administrative credentials. They also attempted to plant backdoors in Terraform configurations, which existing branch protections blocked.

_Developers securing CI/CD pipelines and secrets management can follow findings like this on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#cloud](https://daily.dev/tags/cloud), [#ai-agents](https://daily.dev/tags/ai-agents), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs","url":"https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1"},"datePublished":"2026-09-03T09:44:28.500Z","dateModified":"2026-09-03T11:25:00.305Z","description":"Palo Alto Networks' Unit 42 documented a ransomware intrusion where AI agents compressed what would normally take human operators about two weeks into under 10...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cad3514604861108df0be6c4eb63889f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cad3514604861108df0be6c4eb63889f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cloud,ai-agents,ransomware","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos-rt3twzbf1#faq","mainEntity":[{"@type":"Question","name":"How much faster was the AI-assisted ransomware attack compared to a typical human-led intrusion?","acceptedAnswer":{"@type":"Answer","text":"The attack was completed in under 10 hours, compared to an estimated two weeks for similar work by human operators, according to Palo Alto Networks' Unit 42 team. The intrusion involved more than 50 techniques mapped to the MITRE ATT&CK framework, with AI agents interpreting results and adapting subsequent steps during the attack. Security teams tightening detection-to-containment windows against faster attacks can track this research on daily.dev."}},{"@type":"Question","name":"What is transitive authority in cloud and identity security?","acceptedAnswer":{"@type":"Answer","text":"Transitive authority describes a situation where access in one system enables a more privileged action in another, even without direct permissions. For example, a repository account without cloud administrator privileges could alter a workflow that assumes a more powerful cloud role, so entitlement reviews should assess what an identity can cause other systems to do, not just what it can access directly. Teams reviewing entitlements across dev and cloud environments follow analyses like this on daily.dev."}},{"@type":"Question","name":"How did attackers exfiltrate cloud access keys in the AI-assisted ransomware intrusion analyzed by Unit 42?","acceptedAnswer":{"@type":"Answer","text":"Attackers hijacked an enterprise code application through custom workflows to exfiltrate cloud access keys, after AI agents searched source-code repositories for exposed credentials and used those to breach a secrets-management system and obtain administrative credentials. They also attempted to plant backdoors in Terraform configurations, which existing branch protections blocked. Developers securing CI/CD pipelines and secrets management can follow findings like this on daily.dev."}}]}
```

