Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityai-platform-securitycybercrime-service-ecosystemgovernment-diplomatic-threat

AI-driven shifts in cybersecurity: agentic AI risks, AI-assisted offensive tradecraft, and evolving cybercriminal ecosystems

Updated 3mo agoFirst seen Feb 4, 20264 sources

Security reporting and research highlighted how AI and automation are reshaping both attacker tradecraft and defender operations, while introducing new enterprise risk. ZDNET described research findings that agentic AI implementations from ServiceNow and Microsoft can be exploitable, warning that broadly permissioned agents could enable lateral movement and privilege escalation across systems of record if an attacker compromises an agent or chains between agents with different access levels; a least-privilege posture for agents was emphasized. Dark Reading separately reported that AI agents are increasingly augmenting—and in some cases supplanting—human penetration testing for “low-hanging” vulnerabilities, but that false positives and the need for human oversight remain material constraints as agentic testing matures.

Threat-intelligence coverage also underscored the industrialization of cybercrime and the ecosystems enabling it. CloudSEK detailed the evolution of the English-speaking cybercriminal milieu known as “The COM,” tracing its roots in OG-handle trading communities and forum migrations into a service-oriented underground linked to groups such as Lapsus$, ShinyHunters, Scattered Spider (UNC3944), and Silent Ransom Group, and associated activity spanning breaches, extortion, SIM swapping, ransomware, and crypto fraud. SC Media’s commentary similarly described a cyber underground where criminals can readily buy capabilities (credentials, tooling, automation), calling out techniques including carding and ClickFix social engineering that tricks users into running copied commands to install infostealers. Separately, Dark Reading reported allegations that the Chronus Group posted 2.3TB of purported Mexican government data affecting up to 36 million people, while Mexico’s ATDT disputed it as largely repackaged data from prior breaches and said no new sensitive accounts were identified and that impacted systems were primarily obsolete, third-party-administered state-level platforms.

Share:
AI-driven shifts in cybersecurity: agentic AI risks, AI-assisted offensive tradecraft, and evolving cybercriminal ecosystems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 4, 20265mo ago

Microsoft advises customers to disable risky Connected Agents before publishing

Microsoft issued guidance telling customers to disable Connected Agents before publishing agents that use unauthenticated tools or access sensitive knowledge sources. The company also noted that Entra Agent ID provides identity and governance controls but does not automatically generate alerts without additional monitoring.

Zenity Labs demonstrates Microsoft Copilot Studio Connected Agents risk

Zenity Labs showed that malicious agents in Microsoft Copilot Studio could connect to legitimate higher-privilege agents through the 'Connected Agents' capability. Zenity and Microsoft characterized the issue as a risky design or feature pattern rather than a traditional software vulnerability.

AppOmni Labs discloses ServiceNow 'BodySnatcher' findings

AppOmni Labs publicly disclosed details of the severe ServiceNow 'BodySnatcher' issue, warning that agentic AI integrations can create exploitable privilege-escalation and lateral-movement paths. ServiceNow said it was unaware of any in-the-wild exploitation at the time of reporting.

Oct 1, 20259mo ago

ServiceNow patches the 'BodySnatcher' AI agent vulnerability

ServiceNow says it fixed a severe vulnerability dubbed 'BodySnatcher' in October 2025. According to AppOmni Labs, the flaw could have allowed an unauthenticated attacker with only a target email address to impersonate an administrator, run an AI agent, bypass controls, and create full-privilege backdoor accounts.

Jun 1, 20251y ago

CloudSEK reports emergence of 'Scattered Lapsus$ Hunters' coalition

CloudSEK says a coalition called 'Scattered Lapsus$ Hunters' emerged in mid-2025, combining social engineering, large-scale data exfiltration, and public extortion tactics. The report links the group to high-profile campaigns, including an alleged compromise affecting the Salesforce ecosystem.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

58 LINKEDOpen in app
Malware
3 linked
Affected products
10 linked
InstagramFacebookWhatsappTelegramCloudflareGithubDiscordTorTiktokGithub
Organizations
36 linked
SalesforceBT GroupBlizzard EntertainmentRockstar GamesMegaNvidiaAmazon Web ServicesXBOWHackerOneSamsung ElectronicsJaguar Land RoverCloudflareDriftSalesloftBugcrowdForescoutTikTokMeta PlatformsLouis VuittonEeXMicrosoft CorporationQantasCobaltGucciGoogleUber TechnologiesTokopediaMalaysia AirlinesMachinimaEC-CouncilDaybreak Game CompanyXbox LiveNitro PDFTravelodgePlayStation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.