خبروں پر واپس جائیں۔
سیکیورٹیAI Understanding بریفنگ

AI ایجنٹس نے کمپنی کے نیٹ ورک کو 10 گھنٹوں سے کم وقت میں توڑ دیا اور روٹ کریڈینشلز چرا لیے

ایک انسانی حملہ آور جو فرنٹیئر مصنوعی ذہانت کے ماڈلز سے لیس تھا، ایک انٹرپرائز نیٹ ورک میں داخل ہوا اور 10 گھنٹوں سے بھی کم وقت میں روٹ اسناد ضبط کر لی۔

4 min readRead the linked source
Source-provided image accompanying AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials
ماخذ حوالہماخذ ریکارڈ شدہ
پبلشر
cybersecuritynews.com
ماخذ لنک
cybersecuritynews.comhttps://cybersecuritynews.com/ai-agents-breach-company-network/
ماخذ کی قسم
منسلک ذریعہ - بنیادی ماخذ کی حیثیت قائم نہیں کی گئی ہے۔
سیاق و سباقاسے 60 سیکنڈ میں سمجھیں۔

یہاں سے شروع کریں۔

کلیدی شرائط

API (ایپلی کیشن پروگرامنگ انٹرفیس)
ایک سافٹ ویئر سسٹم کے لیے دوسرے سسٹم کو درخواستیں بھیجنے اور اس سے جواب موصول کرنے کا ایک منظم طریقہ۔
مصنوعی ذہانت (AI)
عمارت کے نظاموں کا وسیع میدان جو کاموں کو انجام دیتا ہے جس میں پیٹرن کی شناخت، استدلال، زبان، یا فیصلہ سازی کی ضرورت ہوتی ہے۔
پائپ لائن
پری پروسیسنگ، ماڈل اسٹیپس، اور پوسٹ پروسیسنگ مراحل کا ایک ترتیب شدہ ورک فلو۔
اپنے آپ کو جانچیں۔اے آئی ایجنٹس کوئز

کیا ہوا؟

A human attacker used frontier AI models to breach an enterprise network and steal root credentials in under 10 hours. The attacker used AI agents to automate the intrusion, compressing more than 50 distinct MITRE ATT&CK techniques into a single automated loop.

The attacker used frontier AI models to breach a publicly accessible web service and gain initial access to the network.

The AI agents then tunneled into the network and deployed an automated reconnaissance agent to map internal microservices.

Sub-agents combed through enterprise code repositories, harvesting hard-coded tokens and service passwords.

The attacker used the exposed tokens to infiltrate the organization's secrets management system and extract master administrative credentials.

The agents hijacked the company's CI/CD through custom workflows to exfiltrate cloud access keys and attempted to plant backdoors inside Terraform infrastructure-as-code configurations.

The attacker seized control of the victim's AI infrastructure and repurposed the company's own compute resources to support future stages of the attack.

ماخذ کی تفصیلات: cybersecuritynews.com ↗

یہ کیوں اہمیت رکھتا ہے۔

The attack highlights the increasing threat of AI-assisted cyber attacks, which can be faster and more efficient than traditional human-led attacks. Organizations must be prepared to counter machine-speed attacks by deploying synchronized containment playbooks, treating AI models and API keys as core infrastructure, and enforcing mandatory multi-party code review.

The attack highlights the increasing threat of AI-assisted cyber attacks, which can be faster and more efficient than traditional human-led attacks.

Organizations must be prepared to counter machine-speed attacks by deploying synchronized containment playbooks.

Treating AI models and API keys as core infrastructure is crucial to preventing AI-assisted attacks.

Enforcing mandatory multi-party code review on infrastructure-as-code repositories can help block automated backdoor injection.

Interactive Mechanism

انٹرایکٹو میکانزم: یہ اصل میں کیسے کام کرتا ہے۔

اس ترقی کے پیچھے بنیادی ٹیکنالوجی کو انٹرایکٹو طریقے سے دریافت کریں۔

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
انٹرایکٹو تصور چیک+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

آگے کیا دیکھنا ہے۔

The use of AI agents in cyber attacks, the potential for AI-assisted attacks to bypass traditional security measures, and the need for organizations to adapt their security strategies to counter machine-speed attacks.

The use of AI agents in cyber attacks and the potential for AI-assisted attacks to bypass traditional security measures.

The need for organizations to adapt their security strategies to counter machine-speed attacks.

The importance of deploying synchronized containment playbooks and treating AI models and API keys as core infrastructure.

متعلقہ گائیڈز اور کوئزز

اے آئی ایجنٹساے آئی سیکیورٹیآپ جو جانتے ہیں اس کی جانچ کریں - ایک مفت AI کوئز آزمائیں۔ہماری لغت میں AI کی اصطلاح دیکھیںاے آئی ریگولیشن ٹریکر پر عمل کریں۔
یہ مفید پایا؟