The Maivia Gazette

Verified AI news, every morning

Security

Google says attackers now run agentic AI campaigns in under six hours

The Google Threat Intelligence Group's quarterly report describes a shift from prompting to autonomous agents, and a China-linked group targeting North American AI research.

Overhead view of mechanical arms picking brass keys off a conveyor belt in a dim teal server hall beside an emptying hourglass.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Google's Threat Intelligence Group said in its latest quarterly report on Tuesday that forward-leaning adversaries have moved from basic prompting to agentic AI workflows and AI-enabled automation since its May 2026 report. In the second quarter of 2026 the group observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. Google says the reduction in human-in-the-loop latency compresses the window defenders have to respond. The report also tracks a group it calls UNC6780 using multiple tactics to trick AI coding assistants and large language model security scanners during open source software supply chain compromises. Adversaries are increasingly targeting AI assets themselves: proprietary models and source code, API credentials, and victim cloud environments co-opted to run unauthorized AI workloads. Google says model weights and cloud compute quotas are now high-value targets for espionage, extortion, and resource theft. NBC News reports that the groups involved include both intelligence agencies and cybercrime gangs, and that one Chinese group Google has tracked since 2023 has focused on academic, medical, and military research organizations in North America and specifically pursued proprietary AI research. Google did not name any of the victims. NBC's headline states that Chinese hackers are running AI on stolen networks to avoid detection.

Sources

  1. NBC NewsChinese hackers are running AI on stolen networks to avoid detection, Google saysPublished · fetched
  2. Google CloudGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI | Google Cloud BlogPublished · fetched
  3. The Hacker NewsAutonomous AI Agents Compromise Thousands of Credentials in Under Six HoursPublished · fetched

Also in this edition