← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 8, 2026 · 14:00via Mandiant / Google TI

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Brief

Executive Summary

Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond.

In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. We also tracked UNC6780 using multiple tactics to trick AI coding assistants and large language model (LLM) security scanners into its open source software supply chain compromises.

Threat actors are also increasingly targeting AI assets.

Read more on Mandiant / Google TI