#NSBCS.143 - Defensive Tips for Combatting Agentic AI Attacks

 

Note: No AI was used in writing this article. Any grammar mistakes are fully made by silly humans.

From our lived experience responding to cyber incidents, we are seeing first-hand the impact agentic AI is making in assisting threat actors in their nefarious activities. What were previously common human-operator errors (e.g. mistyped commands, wrong scripts to execute on an operating system) are now turning into more AI-assisted operators performing actions with fewer mistakes and at much higher velocity.

Whilst not a comprehensive list of everything you should do (and the basics of cybersecurity still apply), here are some helpful tips to defend against agentic AI-powered cyber attacks in your organisation's environment.

1. 'Assume Breach' and defend in layers

In these times of AI-powered business email compromises, countless software supply chains attacks (looking at you, npm), vulnerabilities discovered at an accelerated pace by every person and their dog, and vibe-coded development, it is naïve to assume your organisation will never get hacked. As such, your defence should never solely exist on your outer layer.

A key way to combat this is to 'assume breach'. An example of this is to shift your mindset to thinking "What happens if a specific computer, server, user, service account, API key, third party gets compromised? How much damage can occur?".

Whilst more of a mindset than a technical control you can just switch on, thinking with an 'assume breach' mindset opens your mind to the different layers in your environment, what weaknesses could potentially exist and exploited, and how to start defending those inner layers. This goes hand-in-hand with enforcing least privilege and segmentation discussed below.

2. Enforce Least Privilege and Segment Appropriately

'Least Privilege' is certainly not a new concept, as Cyber and IT professionals have been talking about this for decades. As the name suggests, it involves whittling down the privileges of a user or system to the minimum permissions required for their role or task. For example, is it appropriate for someone in the public relations department at NSB Cyber to hold full administrator access to the IT environment?

'Segmentation' refers more to the logical, connectivity boundaries that exist. This can refer to more than just traditional network segmentation. For example, it may be important to segment different workloads into different AWS accounts. Or segmenting applications so they are hosted on different cloud providers.  An example of segmentation is considering whether a low-cost IoT device really needs to be connected to the same network as critical servers or have access to a highly privileged service account. Probably not, right?

How is this relevant to agentic AI? If you practice 'assume breach', enforce least privilege and segment appropriately,  even if you encounter an agentic AI attack in the middle of the night in part of your environment, you could perhaps rest a bit easier knowing you have sound controls that would limit the blast radius.

3. Automate Responses and Honey Pots

Automated actions to block high velocity automated attacks. Makes sense, right?

Based on our experience, the use of agentic AI has not been particularly stealthy by threat actors; instead, it trades it off for speed. Unfortunately, without automated actions, even if alerted, a sleepy human will be hard-pressed to match the speed of agentic AI on a 3am on a Friday, so you need a baseline of triggers for when to take automated actions as well as the automated actions to respond with.

A honeypot also works hand-in-hand with the automated actions. Honeypots are a concept rather than a specific tool or technology, and can range from fake AD accounts, servers, network ports, canary files and so on. As a sneaky defender, if you can slip in certain fake identities and servers that no ordinary user should be accessing, you can build in automated defences to take action against the source that attempted to access them, and trigger an incident investigation.

4. Establish known acceptable AI usage patterns, and block and respond to deviations

The reality is, in most organisations, people are using AI quite frequently. However, consider carefully whether many of the people really need 'agentic AI' as part of their role. Or if they do, provide them a way to perform agentic AI development safely and in a controlled way that establishes the known, approved baseline, and block and respond to anything that falls outside.

As an example: An alert fires off which identifies a Claude agent running powershell commands on a corporate machine, by a User X who is in a Finance role. Your organisation's acceptable baseline is "Company only approves Copilot for AI usage. Additionally, User X is not in the approved list for agentic AI usage, nor does their role require this. Finally, all agentic AI must only be done on the AWS development environment".  Having a clear baseline about known approved agentic AI usage suddenly turns a somewhat ambiguous alert to a much clearer alarm.

AI isn't going away anytime soon, and neither are AI-powered cyber attacks. Stay up-to-date in forming your cyber resilience, and continue to adapt your defences.


What we read this week

  • OpenAI AI Agent Infiltrates Australian Medicare Statistics Portal - Australian Prime Minister Anthony Albanese has revealed that an OpenAI AI agent gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal, administered by Services Australia, in June 2026. The agent, tasked with researching public medical spending, accessed both public and non-public files. No personal information is believed to have been compromised and there is no evidence of broader network compromise, though a forensic investigation supported by the Australian Signals Directorate is under way. OpenAI took approximately three months to notify the government. Albanese expressed extreme concern to OpenAI CEO Sam Altman over both the incident and the delayed notification. Organisations and agencies should prioritise monitoring of AI agent behaviours and strengthen access controls on public-facing statistical portals.

  • ACSC Warns of Active Exploitation of Critical Adobe Commerce and Magento Vulnerability - The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a critical alert regarding active exploitation of CVE-2026-75650, an improper neutralisation of special elements in a template engine flaw affecting Adobe Commerce and Magento Open Source. The vulnerability enables unauthenticated remote code execution when the /graphql endpoint is exposed. A patch (hotfix) was released on 7 September 2026. The ACSC notes a substantial number of potentially vulnerable instances within the Australian economy and urges system owners to apply the vendor mitigation as a priority. No specific industry or sector has been identified as targeted. E-commerce operators should patch immediately, rotate encryption keys and associated credentials, and hunt for signs of compromise.

  • ShinyHunters Claims Breach of FBI Systems via Oracle PeopleSoft Zero-Day - The cyber extortion group ShinyHunters has claimed it compromised FBI systems by exploiting a previously undisclosed zero-day vulnerability in Oracle PeopleSoft, allegedly stealing 2–3 TB of data including sensitive personnel and applicant information on current and former agents (names, addresses, phone numbers, spouse details and certain medical information). The group defaced the FBIJobs.gov portal and stated the action was not financially motivated but aimed at securing the retraction of an earlier FBI advisory about the group. Sample data provided to journalists has been partially verified. The FBI is actively investigating the claimed compromise of the jobs portal and alleged impact on employee personally identifiable information. Organisations using PeopleSoft should prioritise monitoring for related indicators and apply any available patches promptly.

  • Microsoft Disrupts EvilTokens AI-Powered Phishing-as-a-Service Platform - Microsoft’s Digital Crimes Unit, working with partners and UK law enforcement, has disrupted EvilTokens (tracked as Storm-2992), an AI-assisted phishing platform that compromised more than 12,000 Microsoft email inboxes across over 10,000 organisations worldwide. Australia ranked among the top victim countries alongside the US, Canada, UK, India and France. The service, launched in February 2026 and sold via Telegram for an initial US$1,500 fee plus monthly charges, used device-code phishing and an AI chatbot to analyse compromised inboxes, identify trusted contacts and recommend fraud strategies. Fifty websites were seized and more than 150 domains disabled; two men were arrested in the UK. Organisations should enforce phishing-resistant multi-factor authentication, monitor for anomalous OAuth/device-code activity and educate users on unexpected authentication prompts.

  • Gyazo Data Breach Exposes 23.6 Million User Records and Hundreds of Millions of Image Metadata Entries - Japanese firm Helpfeel has confirmed that attackers exploited a vulnerability in the Gyazo image-sharing service’s upload server on 11 September 2026, leading to the unauthorised disclosure of approximately 23.62 million user records (names/nicknames, email addresses, password hashes, device and session IDs, and certain integration tokens) and roughly 490 million image metadata records, primarily relating to content uploaded on or before January 2019. No payment card details were exposed. The company has advised all users to change passwords and has temporarily restricted viewing of some images. Users of the platform should rotate credentials, review connected accounts and consider the privacy implications of any stored screenshots or captures.


Next
Next

#NSBCS.142 - When AI Escapes the Sandbox