The most unsettling number in cybersecurity right now is not days or weeks, but hours. In a recent investigation by Palo Alto Networks' Unit 42, researchers responded to an enterprise intrusion where a human threat actor used frontier AI models and attack-specific agentic frameworks to automate a significant portion of the attack lifecycle.
The Speed of AI-Driven Attacks
The intrusion lasted only 10 hours, a timeframe that compresses what used to take days or even weeks of manual effort. The attacker did not rely solely on automated scripts but used agentic frameworks that allowed AI models to make decisions and adapt to the environment. This suggests a shift from static automation to dynamic, AI-assisted operations.
Implications for DevSecOps
For developers and security teams, this case study highlights a critical gap in traditional monitoring. If an attacker can navigate an enterprise network and execute key objectives in under a day using AI agents, standard alerting thresholds may be too slow.
What This Means for You
The human element remains in control, directing the AI, which makes the attack harder to predict than fully autonomous malware. Security teams must prepare for adversaries who augment their speed with AI rather than replacing human intuition entirely.
Key Takeaways
- Human-led AI agents can reduce intrusion dwell time to 10 hours.
- Attack-specific agentic frameworks are being used to automate decision-making.
- Traditional detection methods may need to accelerate to match AI-driven speeds.
The Bottom Line
The barrier to entry for sophisticated, rapid intrusions is lowering. We are no longer just fighting code; we are fighting AI-augmented humans who can move faster than our current pipelines can log.