--- source: https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ created: 2026-08-08T11:38:00 --- **Chen Doytshman** — security researcher with a background in artificial intelligence and machine learning, passionate about using AI to protect against cyber threats. Over 5 years of experience combining security and AI to identify and mitigate vulnerabilities. Audience: Offense/Red Team, Defense/Blue Team, Cloud, AppSec, AI, SecOps, Purple Team ## Overview In November 2025, Anthropic disclosed a state-sponsored operation where AI didn't assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from "could this happen?" to "how bad can it get?" We built Zealot to find out. Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does. In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set. We'll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short *(source abstract cuts off here)*. ## Notes *(No live notes captured for this talk. See the companion research writeup at the source link above.)*