AI-powered hackers level up: autonomous agents and 'phantom squatting' redefine the cyber arms race

The Hacker News

The gist

Autonomous AI agents are supercharging cyberattacks, arming small-time hackers with nation-state-level firepower and forcing banks to rewrite their playbooks overnight.

What to know

AI Arms Race Goes Local

Autonomous agents and new tactics like phantom squatting are putting nation-state-level cyber capabilities into the hands of solo hackers, fueling a surge in scalable, unpatchable attacks.

AI is dramatically lowering the barriers to entry for sophisticated cyberattacks, effectively democratizing offensive capabilities that were once the exclusive domain of elite nation-state actors. As Australia’s ASIC commissioner warned, the real threat now comes from individuals or small groups in garages who can quickly assemble and weaponize AI-driven tools. This shift means defenders must now anticipate attackers wielding capabilities that resemble yesterday’s nation-state arsenals, with AI automating and scaling operations such as vulnerability scanning, exploit chaining, and adaptive attacks, intensifying the dual-use dilemma in cybersecurity.

Agentic AI represents a paradigm shift by enabling autonomous cyberattacks that require no human intervention, accelerating offensive operations and expanding capabilities to previously unskilled actors. According to recent analyses, these AI agents can continuously execute complex campaigns—gathering intelligence, crafting personalized phishing messages, and exploiting vulnerabilities faster than defenders can respond. This automation not only grants ferocious speed to seasoned attackers but also empowers entry-level threat actors who now need only intent and access to capable AI tools, effectively transforming the cyber threat landscape.

Emerging attack techniques like 'phantom squatting' exploit inherent hallucination tendencies in large language models to generate and preemptively register fake domains, which attackers use for phishing, malware distribution, and supply chain attacks. Palo Alto Networks’ Unit 42 uncovered over 13,000 confirmed malicious URLs and hundreds of thousands of unregistered AI-generated domains, highlighting how this structurally unpatchable vector leverages AI’s own outputs as inputs for malicious use. This novel approach not only expands the attack surface but also accelerates the cyber arms race by shrinking defenders’ reaction times and democratizing domain-based attack capabilities.

AI-driven offensive tooling is rapidly evolving beyond traditional malware, with attackers employing promptware attacks that manipulate AI agents’ logical layers to steal intellectual property without deploying conventional malware. This innovation, coupled with AI’s ability to generate vast variants of obfuscated malware at machine speed, complicates detection and response efforts. While behavioral detection and established runbooks remain effective against many Tier 1 threats, the continuous, autonomous, and multi-agent orchestration of attacks—exemplified by nation-state groups leveraging Entropic’s AI models—intensifies the cyber arms race and challenges defenders to keep pace.

Sources

Defensive Playbook Overwhelmed

Legacy security frameworks and human-centric controls are collapsing under the explosive growth of AI-powered attacks, forcing defenders to rethink detection, patching, and internal AI agent oversight.

Defenders face a critical challenge in accessing the most advanced AI models essential for scaling pattern recognition, anomaly detection, and accelerating vulnerability discovery. Partners leveraging models like Claude have identified over 10,000 high-and-critical-severity vulnerabilities in a single month—a tenfold improvement over traditional methods—highlighting AI’s potential to help close the average 43-day gap between discovery and remediation. As Jen Easterly emphasizes, defenders hold a structural advantage through legitimate system data, but this edge can only be realized if cutting-edge AI tools are democratized and integrated into cybersecurity products and CISO toolkits.

The rapid evolution of AI-orchestrated attacks exposes fundamental limitations in traditional defense frameworks like MITRE ATT&CK, which lack the vocabulary to address autonomous orchestration—the true risk multiplier in modern cyber threats. Security experts now advocate shifting detection paradigms from isolated techniques to behavioral patterns such as attack tempo and orchestration interfaces, employing UEBA and sequence-aware detection to identify machine-speed attack chains. This transition is imperative as attackers autonomously chain exploits at speeds compressing response windows from weeks to mere days or hours, forcing enterprises to accelerate patching cycles and rethink vulnerability prioritization beyond checklist approaches.

The surge of autonomous AI agents within enterprises—growing over 466% year-over-year according to BeyondTrust’s Phantom Labs—creates a sprawling 'shadow AI workforce' that vastly outnumbers human users and introduces unprecedented security challenges. Traditional models based on human-centric controls are inadequate, necessitating real-time enforcement mechanisms like BeyondTrust’s AI Agent Security platform, which acts as a digital governor to enforce least privilege, block unauthorized AI tools, and prevent credential exfiltration. Without granular visibility and control, these AI agents operating with user-level privileges exponentially expand the attack surface, demanding a fundamental shift in enterprise security posture.

As AI accelerates both attack and defense operations, organizations that restrict defender access to advanced AI inadvertently redistribute risk to uncontrolled environments where attackers freely innovate with ungoverned tools. OpenAI’s cyber defense plan exemplifies a strategic pivot by creating verified access lanes for dual-use AI technologies, aiming to democratize AI-powered defense and restore balance in the cyber arms race. This approach acknowledges AI as a force multiplier for both sides, making early and broad access to capable models a critical determinant of defensive success. Ultimately, embracing AI responsibly is not optional but essential, as enterprises that hesitate risk being outpaced by adversaries who wield offensive AI without restraint.

Sources
Resilient CyberIT Brief New ZealandBriefglanceToxSec - AI and CybersecurityIBTHOR Collective Dispatch

Governance Gaps Exposed

AI agents are exploiting outdated trust assumptions and weak oversight, making continuous validation and production-grade governance essential to prevent privilege abuse and systemic breaches.

As AI agents increasingly operate autonomously at machine speed within enterprises, traditional governance frameworks are proving inadequate to manage the resulting risks. Arvind Nithther Kashayup, CTO and co-founder of Rubric, highlights the challenge: 'How do you govern systems that operate at machine speed?' This rapid AI sprawl exacerbates vulnerabilities, as demonstrated by security researcher Ian Carroll’s use of Anthropic's Claude Opus 4.7 to bypass web application firewalls and exploit SQL injection flaws, underscoring the fragility of many critical systems and the urgent need for more robust security paradigms.

A fundamental governance failure lies in organizations’ reliance on outdated trust assumptions, where approved systems continue to be trusted long after their configurations or roles have changed. As noted in a 2026 opinion piece, 'modern attackers aren’t breaking trust—they’re inheriting it,' exploiting these stale relationships to penetrate defenses. This dynamic calls for continuous validation of trusted relationships and the adoption of zero trust models that treat every access request as potentially hostile, thereby mitigating risks introduced by AI-driven automation.

To effectively manage AI-driven risks, enterprises must elevate governance controls to the level of production code management, treating AI agents as privileged identities subject to strict approvals, logging, least privilege, and change control. Many organizations currently allow AI agents to autonomously consume changing tool descriptions without oversight—a glaring governance gap rather than a technological limitation. Donald Coddling emphasizes that identity verification alone is insufficient in this AI-accelerated trust crisis; instead, relationship verification tied directly to authority and permissions is essential to establish digital trust and psychological safety.

Sources
N2K NetworksCISO Talk by James Azar

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.