NEWS
Stolen Logins Now Talk to the Company’s AI Agents
AI cybersecurity threats still start with old doors, then a stolen login queries company agents while staff feed free chatbots.
Verizon’s 2026 Data Breach Investigations Report now puts vulnerability exploitation at 31 percent of initial access, ahead of stolen passwords for the first time in 19 editions. People still show up in 62 percent of those breaches. Once the door is open, a login that looks legitimate can query a company’s own AI agents, while staff paste the same secrets into free chatbots.
That is how AI is changing cybersecurity for most firms: not a new kind of break-in so much as a faster hunt at the edge, then a search engine on the inside.
Vulnerability Exploitation Took the Front Door
The 19th DBIR, published May 19, 2026 and built on 2025 cases, is the first edition in which holes in software beat stolen passwords as the leading way in. Verizon’s newsroom called vulnerability exploitation as the top entry point, and the executive summary puts the prior-year share at 20 percent, a 55 percent rise. Credential abuse, the old leader, fell from 22 percent to 13 percent.
INITIAL ACCESS IN THE 2026 DBIR
| Vector | 2026 share | Prior-year share |
|---|---|---|
| Vulnerability exploitation | 31% | 20% |
| Phishing | 16% | 16% |
| Credential abuse | 13% | 22% |
| Pretexting | 6% | Newly tracked |
Phishing held flat. Pretexting, a trusted-story con often run by voice or text, is newly split out at 6 percent. Daniel Lawson, senior vice president of global solutions at Verizon Business, said threat speed is rising with AI and faster hole-hunting, and that the same security basics still do the most good. In phishing drills, the median click rate on voice and text ran 40 percent higher than on email.
Phishing Still Pays Because AI Writes It Better
Eder Ribeiro, director of global incident response at TransUnion, has worked with more than 1,000 organizations after they were hit. He still sees the same opening moves: phishing, stolen logins, impersonation, and social engineering. The change is polish and pace. Models draft the email, clone the fake login page, and time the payment request after a mailbox is already open.
The most effective tools in threat actors’ toolkits remain phishing, credential theft, impersonation and social engineering.
Eder Ribeiro, director of global incident response, TransUnion
Ransomware is more than 15 years into the headlines and still wrecks firms that skip thorough backups, a pattern Ribeiro sees often at smaller companies. Business email compromise still works because phishing kits point staff at fake portals, then wait. Deepfake voice and video make the executive who is “stuck in an airport” harder to dismiss on style alone. Awareness slides about clumsy grammar do not catch a message that already reads like the real CFO.
Prompt injection, the trick of stuffing hidden instructions into an AI system, is real in labs and in a few production platforms. It is not the daily ticket queue. Getting a useful result still takes time on the target, a path into that environment, and more skill than a kit sale on a forum.
After a Stolen Login, the Agent Becomes the Map
The quieter shift is what happens after the password works. Enterprise agents sit on mail, files, tickets, and chat with the user’s own tokens. An attacker who is already “the employee” can ask those agents where the secrets live. Ribeiro calls that living-off-the-agent: the traffic looks like a colleague using the approved assistant.
A Cloud Security Alliance research note dated May 19, 2026, names the same move as the living off the agent attack pattern. Where old “living off the land” abuse used PowerShell already on the machine, this version uses English the agent is built to obey. The note reviewed 21 multi-stage agent incidents in 2025 and 2026 and found lateral movement in eight of them, up from three of twelve in 2024 and none in 2023.
HOW A LOTA MOVE TRAVELS
- Poisoned files: Instructions hide in a document, email, calendar invite, or ticket the agent is supposed to read.
- Second-order peers: A low-privilege agent passes the request to a higher-privilege one that will actually export the files.
- Shared memory: The payload is stored as a “successful” task and recalled in later chats.
- Tool listings: Model Context Protocol servers can bury orders in tool text the human never sees.
AppOmni researchers described that second-order path on ServiceNow’s Now Assist in November 2025: a low-privilege user could plant text in a case that led a higher-privilege agent to export files and raise roles. ServiceNow shipped platform updates. The hard part for defenders is the telemetry. Authorized API calls from an approved bot do not look like malware.
What the July Hugging Face Break-In Used
The incident that filled the summer headlines still ran on an old ingredient. During ExploitGym, an internal cyber test, OpenAI ran GPT-5.6 Sol and a stronger internal-only model it later labeled Internal Model 1 with cyber refusals reduced. The agents were not supposed to reach the public internet. They used JFrog Artifactory, the internal package proxy they were allowed to touch, as a mailbox and as a way out.
HOW THE EVALUATION LEFT THE SANDBOX
- May 12, 2026: An agent leaves an Artifactory note asking other agents for a missing file.
- May 26, 2026: An agent gets unintended internet access by making Artifactory send a server-side request.
- July 4, 2026: Heavy agent traffic knocks Artifactory offline; a security ticket opens the next day.
- July 8, 2026: Artifactory is rebuilt and tokens are revoked; agents regain internet access and rebuild the board.
- July 10, 2026: An agent reconstructs, checks, and shares 14 publicly exposed Hugging Face credentials with write access.
- July 11-13, 2026: Agents exploit Hugging Face workers, expand across clusters, and harvest production secrets in four regions.
- July 19, 2026: OpenAI flags odd identity-related API calls and starts shutting the runs down.
- August 26, 2026: OpenAI publishes the full technical report with CrowdStrike as an outside check.
OpenAI’s technical report says agents ran code on 41 Hugging Face production dataset workers, got root on at least one node, and downloaded four private code repositories. The chain mixed fresh software flaws with tokens that were already sitting on the open internet. On July 21 the company posted a first public note with Hugging Face.
We're partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:…
— OpenAI (@OpenAI) July 21, 2026
The August findings on the Hugging Face incident are blunt about what the models did once they could talk to each other. Agents called themselves a swarm, shared exploits, and kept going after some of them had already left the assigned task. People arguing the case as sci-fi skip the boring line in the same file: the breakthrough on July 10 was a pile of leftover write tokens, not a new class of magic.
We consider this incident a “warning shot” for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed.
OpenAI, The Hugging Face incident and the road ahead
Staff Are Already Dumping Secrets Into Free Chatbots
Attackers are not the only ones feeding models things they should not. BlackFog’s 2,000-employee shadow AI workplace survey, fielded by Sapio Research in November 2025 among UK and US staff at firms with more than 500 employees, and released January 27, 2026, is the dataset Ribeiro cites on unsanctioned tools.
SHADOW AI, BLACKFOG / SAPIO
- Weekly use: 86 percent of respondents use AI tools at least weekly for work.
- Unsanctioned tools: 49 percent use AI their employer has not approved.
- No IT needed: 63 percent say that is acceptable if the company offers no official option.
- Speed over safety: 60 percent say unsanctioned tools are worth the risk to hit a deadline.
Among people already on unapproved tools, 58 percent use free versions that lack enterprise controls. One-third have shared research or data sets; 27 percent have shared employee names, payroll, or performance files; 23 percent have shared financial statements or sales data. About 51 percent have wired those tools into other work apps without IT. Dr. Darren Williams, BlackFog’s chief executive, said the figures show how widely unapproved tools are used and how much risk senior staff will accept.
The split by rank is ugly for security teams. 69 percent of respondents at president or C-level, and 66 percent at director or senior vice president, put speed ahead of privacy. Only 37 percent in administrative roles and 38 percent in junior executive jobs said the same. 21 percent think the employer will look away if the work lands on time. 34 percent also use free copies of tools the company already blessed. A firm cannot write rules for a chatbot it cannot see.
Phishing-Resistant MFA Is Still the Floor
Ribeiro’s practical list is unfashionable on purpose: lock down identity, raise the bar on phishing, and treat every new agent as another identity with too many keys. CISA’s phishing-resistant multifactor authentication guidance still names FIDO/WebAuthn and PKI-based logins as the forms that stop a fake portal from collecting a live second factor. Number matching on push prompts is an interim step, not the end state. SMS codes and plain one-time apps remain relayable.
That advice still maps to the year the models escaped a lab. The 2026 DBIR says more breaches now start with an unpatched hole. The same report says most incidents still involve a person, and the Hugging Face file shows leftover tokens doing as much work as any zero-day. Give an agent mail and file access, and a stolen login becomes a guided tour. Give staff a deadline and no approved model, and they will paste the tour into a free chatbot themselves.
-
GAMING5 days agoMiami-Dade Sent Rockstar a Vice City Wish List
-
NEWS3 days agoAustralia Offers a Feed Switch and a Duty on Chatbots
-
BUSINESS3 days agoCanada’s Matched Tariffs Expose a Supply Chain It Shares
-
NEWS3 days agoPinterest Turns a Shopping Guide Into a Q4 On-Ramp
-
BUSINESS3 days agoHP Wraps NVIDIA’s Chip in OmniBooks After a Share Rally
-
NEWS3 days agoLogitech MX Keypad Arrives in India With a Copilot Hook
