← All Briefings
Briefings


AI Agents Ran A Ten-Hour Breach Across Cloud, Identity, CI/CD

The incident researchers disclosed on September 2 ran a multi-agent frontier AI system against a single enterprise target and moved from initial access to full compromise of cloud infrastructure, identity systems, and the CI/CD pipeline in under ten hours, chaining more than 50 MITRE ATT&CK techniques along the way. Dark Reading's writeup calls the comparison point a "two-week attack," the kind of timeline a human red team or intrusion crew needs to do equivalent reconnaissance, lateral movement, and privilege escalation by hand. The AI system produced an 80-page audit trail of its own actions. That log is the artifact worth reading before the vendor summary: it names which of the 50-plus techniques chained into privilege escalation on identity infrastructure, and identity is the layer that turns a single compromised account into control of everything downstream.

No named CISA advisory or CVE accompanies this one yet, which is itself the finding. A technique count and a ten-hour clock are not the same as a patchable flaw, and a security team briefing its board on September 4 cannot point to a single control that would have stopped this the way MFA stops a credential-stuffing run. The closest available lever is detection speed: an environment tuned to flag CI/CD pipeline changes and identity privilege escalations within minutes, not the hours a ten-hour compressed attack still needs to complete each stage, is the only control category that scales to machine-speed intrusion. Boards asking "are we exposed to this" this week should be asking their SOC how fast that specific alert fires, not whether they have a patch to apply.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.