Are AI agents proving to be a headache for enterprise cybersecurity?

Applications of AI


As 2025 draws to a close, Anthropic makes a shocking claim on its blog that Chinese state-backed bad actors are leveraging the coding capabilities of its AI chatbot Claude to carry out cyberattacks. To make matters worse, all of these threats were carried out autonomously against technology companies, financial institutions, and government agencies.

“In mid-September 2025, we detected suspicious activity, which upon further investigation revealed to be a highly sophisticated espionage operation. The attackers took advantage of the ‘agent’ capabilities of AI to an unprecedented degree. They used AI not only as an advisor, but also to carry out their own cyber attacks,” the blog said.

More recently, Anthropic has used these highly agentic features to make Claude the preferred coding assistant for a wide section of enterprise operational workflows. The results were shocking enough for investors to speculate that this development could spell the end of IT services as we know them. And some IT stocks plummeted.

Cybercriminals have been using AI since 2018

However, this was not the only time warning shots were fired. A few weeks ago, Google’s Threat Intelligence Group claimed that state-sponsored threat actors and some freelance cybercriminals were experimenting with AI and large-scale language models to run malware at scale.

The hype cycle reached a feverish climax when Anthropic claimed that one of its teams had analyzed data and discovered that blockchain could be exploited by using AI to discover zero-day vulnerabilities. These were used to exploit approximately $4.6 million worth of smart contracts, they said in a separate blog dated December 1, 2025. Did this injection coincide with the crypto meltdown?

Of course, security analysts are quick to point out that malicious uses of AI do not occur routinely and are largely hypothetical in nature.

However, as reasoning abilities have improved, so has its use in crime. According to the report, users in countries where AI chatbots are banned ended up circumventing controls and accessing them.

The use of OpenAI by Iranian military and North Korean hacker groups to create phishing emails was reported by the Microsoft Threat Intelligence Center two years ago. These are examples of Gen AI being used to generate cyber attacks. Readers may recall a DDoS attack on an IKEA-owned service platform in 2018 that stole customer names, passwords, and payment details.

Security experts argue that while these past incidents demonstrate advances in the underlying technology, as with AI as an entity, things are becoming more nuanced. Criminals can now use a Python installer on a system without the malicious code and write code that prompts it to connect to the Hugging Face API and “profile the system.”

Then the program scans your system to find interesting information in the form of files, bundles it and deletes it from your system and saves it in another location. Importantly, all of the above can be achieved with agent AI. Adam Myers, Head of Adversary Countermeasures at CrowdStrike, recently told SDX Central that they haven’t detected anything so far and that this is probably the most advanced AI cybercrime effort yet.

What was the software installer called? LameHug – Criminals have a sense of humor.

Some time ago, Ukraine claimed that Russian security services used LameHug to target its military. It was later noted that the company’s computer emergency response team, CERT-UA, discovered the attempt in a timely manner.

Cyber ​​experts believe that while there have been attempts in the past to use AI to spread misinformation or obtain some data in the form of customer names or email IDs, the use of agent AI to complete tasks intuitively and anonymously is now a challenge for businesses to recognize.

They note that in yet another tactic, cybercriminals are using AI chatbots to generate PowerShell scripts or similar code snippets on the fly. These represent a large part of how AI is being integrated into enterprise workflows. Of course, in all of these cases, the caveat is that humans continue to direct operations at critical moments.

A recent analysis by Forrester, based on Agentic AI Enterprise Guardrails for Information Security (AEGIS), states that these efforts are “for security purposes,” one of the defining features of AI security. “Securing intent is not just an issue for LLM vendors; it is a top priority for any organization building an AI agent and is one of the defining capabilities of AI security,” the research firm said.

In fact, the paper argues that Claude may have exaggerated findings and fabricated data during such autonomous operations. They also pointed out that all claimed results will now require careful verification.

“While the attack itself used existing exploits and was not fully autonomous, it is important to note that this serves as a harbinger of future attacks using AI and agents. As with past technological advances, malicious actors will continue to refine these capabilities,” the report concludes.



Source link