By NHI Mgmt Group Editorial TeamBased on Silverfort: “What the first agentic cyber campaign really means for defenders” (November 17, 2025)

TL;DR: AI powered attackers are using agentic reasoning to run reconnaissance, privilege exploration, and lateral movement as one compressed intrusion chain, collapsing breakout time to minutes according to Silverfort’s analysis of Anthropic’s investigation. Detection-led security loses its timing anchor when the attacker moves at machine speed, and identity controls must become the primary enforcement point.


At a glance

What this is: This is an analysis of AI-orchestrated intrusion chains and the finding that agentic automation can compress reconnaissance, privilege exploration and lateral movement into minutes.

Why it matters: It matters because IAM, PAM and NHI programmes that rely on detection latency and human-paced review lose effectiveness when adversaries operate at machine speed.


Context

AI orchestrated intrusion chains are a security and identity problem when attackers use reasoning systems to accelerate the full kill chain rather than a single step. In this article, the issue is not a new exploit class but the collapse of timing assumptions inside detection-led security and human-configured IAM.

Silverfort’s analysis of Anthropic’s investigation frames the core failure as trust and access design that still assumes human behaviour. When identity paths, internal APIs and privilege relationships are permissive, agentic automation can move through them faster than security teams can correlate alerts or intervene.


Key questions

Q: How should security teams stop AI orchestrated intrusion chains from bypassing IAM controls?

A: They should enforce context-aware decisions in the access path, not after the fact. Inline authentication and authorization controls can challenge unusual velocity, repeated API behaviour, and identity jumps across systems before an attacker completes the chain. The goal is to interrupt continuity, because machine-speed intrusion wins when identity controls react too late.

Q: Why do static IAM and permissive trust paths increase risk against agentic attackers?

A: Because they create durable bridges that an adaptive attacker can reuse across systems without needing a new exploit at each step. When entitlements, internal APIs and machine identities are trusted by default, the intrusion becomes a trust exercise rather than a technical breakout, which dramatically lowers the cost of lateral movement.

Q: What are the signs that detection-led security is failing against machine-speed intrusions?

A: The clearest signs are alerts that arrive after multiple steps have already happened, repeated access bursts that outpace human review, and attack paths that move across identities or services before analysts can correlate them. If the chain is always complete before response begins, the control model is too slow.

Q: How should security teams adapt IAM and NHI controls to machine-speed attacks?

A: Security teams should move from periodic review to continuous governance of access paths, especially for secrets, service accounts, and delegated sessions. The goal is to reduce the usable time window for abuse, automate revocation where possible, and make privilege scope narrow enough that compromise does not automatically become lateral movement.


Technical breakdown

How agentic intrusion chains compress reconnaissance through lateral movement

An intrusion chain becomes materially different when an AI system can reason about tool outputs, choose the next action and continue without human pacing. In the campaign described, the agents combined reconnaissance, vulnerability scanning, information gathering, privilege exploration and parts of lateral movement into a compressed sequence. The technical shift is not new tactics, but the removal of analysis delay between stages. That matters because every stage now feeds the next almost immediately, which reduces the time defenders have to build a coherent detection story from separate signals.

Practical implication: Design controls that can interrupt access attempts inline rather than waiting for post-event correlation.

Why static IAM and permissive trust paths become attack infrastructure

Static IAM becomes dangerous when permissions accumulate, machine identities gain broad reach and internal APIs trust anything that appears to be inside the perimeter. The article describes an environment where long-standing trust paths, fragmented access control and broken automation gave the attacker a continuous route through the estate. In practice, the weakness is not one misconfiguration but a layered trust fabric that was never built to re-evaluate context at machine speed. Once an AI system can reuse tokens, call internal APIs and traverse systems without friction, the access model becomes part of the attacker’s infrastructure.

Practical implication: Treat identity context, API trust and entitlement scope as live enforcement points, not fixed provisioning decisions.

Detection-led security fails when the attacker removes human timing markers

Detection systems are tuned to human behaviour because human operators pause, generate noise and reveal patterns that can be correlated over time. Agentic operations strip out those markers. The result is a kill chain that advances before alerts can assemble, especially when the attacker can adapt immediately to each response. This is why the timing anchor of detection-led security breaks down: the control assumes there will be enough observable delay to recognise malicious intent. When the chain runs at machine speed, the defender sees fragments too late to act as the primary barrier.

Practical implication: Shift from alert-first thinking to continuous identity decisions that can challenge or block abnormal machine-speed behaviour.


Threat narrative

Attacker objective: The objective was to turn identity trust relationships into a machine-speed intrusion path that could reach and move through target environments before detection systems could stop it.

  1. Entry occurred through agent-driven reconnaissance, vulnerability scanning and information gathering against about thirty organisations, allowing the operators to map exposed paths and weak trust relationships.
  2. Privilege escalation followed through identity paths that had grown permissive over time, with the agents exploring access routes and reusing tokens where the environment allowed it.
  3. Lateral movement then happened through long-standing internal trust paths and fragmented access models, enabling the campaign to move across systems faster than human review cycles could react.
  • JADEPUFFER agentic ransomware 2026: The first documented agentic ransomware used harvested keys, default MinIO credentials and a default Nacos signing key to wipe a database.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Detection-led security is no longer the right primary control when attackers can compress the kill chain into minutes. The model depends on human-paced intrusion, enough dwell time for telemetry to accumulate and enough friction for analysts to intervene. Agentic reasoning removes that timing cushion, so the control objective shifts from detection verdicts to inline identity enforcement. The practitioner conclusion is simple: if the response depends on seeing the full attack first, it will often arrive too late.

Static human-configured IAM created the attack surface that machine-speed operations exploited. Permissions that were once convenient became durable trust bridges across environments, APIs and machine identities. The issue is not just over-entitlement, but the assumption that access relationships can remain stable while the threat actor adapts instantly. The implication is that IAM design now has to be measured against adversarial runtime behaviour, not only against provisioning policy.

Identity trust has become the real control plane for agentic intrusion defence. The article is a reminder that attackers do not need novel exploits when the environment already exposes permissive tokens, fragmented access paths and implicit trust inside the perimeter. That creates an identity blast radius problem: one compromised or abused trust path can carry the whole intrusion chain. Practitioners should read this as a governance failure in how trust is distributed, not just a detection gap.

Machine-speed attackers invalidate review-based governance assumptions across IAM, PAM and NHI programmes. Access review processes were designed for privileges that persist long enough to be observed, certified and revoked on a cycle. When an AI-orchestrated intrusion can request, use and move on within minutes, that assumption fails because the risky state may never survive to a review point. The practitioner conclusion is to re-evaluate which controls depend on stable access duration before they can function.

Identity-centric protection is becoming the field’s named concept for this class of threat. The useful idea here is not a new tool category but a control philosophy that treats identity, context and runtime behaviour as the point of intervention. That aligns most closely with OWASP-NHI and zero trust thinking because the attacker’s path runs through trust relationships, not just code flaws. The practitioner implication is to move enforcement into the access flow itself, where the intrusion sequence is still interruptible.

From our research library:

What this signals

Identity trust is now an intrusion surface, not just an authentication concern. When agentic automation can traverse APIs, machine identities and legacy entitlements in one continuous sequence, the programme has to evaluate whether trust paths are still segmented enough to survive adversarial runtime behaviour. That is why zero trust and NHI governance now converge in practice.

Access review cycles are being outrun by execution speed. If a privilege can be acquired, used and discarded before a certifier ever sees it, the control is measuring the wrong thing. Programmes need to focus on issuance-time decisions, runtime context and inline interruption rather than on retrospective validation.

90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs. That figure now reads less like a maturity benchmark and more like a dependency statement: zero trust cannot hold if machine identities remain ungoverned.


For practitioners

  • Strengthen inline identity enforcement Move critical access decisions into the request path so unusual speed, context drift or token reuse can be challenged before the next stage of the intrusion chain completes.
  • Re-map trust paths across environments Inventory which internal APIs, machine identities and entitlement bridges still trust location or legacy status rather than current context and least privilege.
  • Add machine-speed behaviour signals Flag bursts of authentication attempts, repeated API calls and rapid identity hopping as control inputs, not just as detections for later review.
  • Reassess access review dependence Identify IAM, PAM and NHI processes that assume access lasts long enough to be certified, then redesign those decisions for shorter-lived or ephemeral use cases.

Key takeaways

  • AI-orchestrated intrusion chains compress reconnaissance, privilege exploration and lateral movement into a pace that undermines detection-first defence.
  • The article links that compression to permissive identity paths, fragmented access control and machine identities that already held more reach than defenders intended.
  • Practitioners need inline identity enforcement, tighter trust-path segmentation and governance that assumes access may be used and abandoned before a review ever occurs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe article centres on AI-driven execution across reconnaissance and movement phases.
Recommendation — Map agentic intrusion behaviour to ASI02 and block unsafe tool use in runtime access flows.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe campaign exploited trust and authentication paths that were not built for adaptive machine-speed behaviour.
NHI-05 — Overprivileged NHIPermissive entitlements and broad machine reach were part of the attack path.
Recommendation — Apply NHI-04 to challenge abnormal authentication patterns before they become lateral movement. Use NHI-05 to reduce machine identity scope and remove durable bridges across services.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe story is fundamentally about access permissions that outlived their intended trust model.
Recommendation — Apply PR.AA-05 to continuously re-evaluate entitlements against current context and risk.
NIST Zero Trust (SP 800-207)3.1 — Verify explicitlyThe attack succeeded because implicit trust and static timing assumptions remained in place.
Recommendation — Use explicit verification at each request to prevent trust-path abuse across systems.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe campaign combined credential-driven access with movement across connected environments.
Recommendation — Track credential access and lateral movement indicators together to detect compressed intrusion chains.

Key terms

  • Agentic intrusion chain: An agentic intrusion chain is an attack sequence executed by a system that can decide the next step at runtime. It differs from scripted automation because the actor can interpret results, adapt, and continue without human pacing, which makes traditional detection and review cycles too slow to intervene effectively.
  • Internal Trust Path: An internal trust path is the route through which systems or users are allowed to communicate within a network based on assumed trust. When these paths are too open, they let an attacker reuse initial access to reach sensitive services, making containment and monitoring much harder.
  • Detection-Led Security: A security model that assumes alerts, correlation and response can stop an attacker after enough telemetry has accumulated. It works best when intrusions are slow enough to observe, but it weakens sharply when adversaries operate at machine speed and complete multiple stages before analysts can react.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org