AI agents can hack systems and find vulnerabilities. What now? Header image
News & Stories 10 min read

AI agents can hack systems and find vulnerabilities. What now?

Published:Sep 11, 2026

In the past months, the speed of evolution of cybersecurity AI agents has become evident and concerning. From Meta to OpenAI and Anthropic, major AI companies have all recently publicly admitted that their AI agents have hacked other companies, escaped sandboxes, tried to cover up their tracks, and manipulated cloud and credentials.

To add more wood to the fire, a recent UK study evaluating cybersecurity agents was cut short when researchers noticed that data was being transferred out of the system. One of the agents had attempted to merge malware into an open-source GitHub project publicly available online to anyone. The agent created several accounts with fake identities and tried to trick the human in the loop. 

In this report, experts from the Moonlock Lab Team, Socure, and Rubrik talk about agentic cybersecurity today. We cover how it has evolved, whether you should be worried, and where all this tech evolution leaves us. Let’s dive in.

AI cybersecurity agents take a massive quantum jump and tumble

Recently, more than 100 AI and cybersecurity companies, including OpenAI, Anthropic, Amazon Web Services, and Microsoft, warned the federal government that AI attacks could surge in the coming months. The warning comes after big AI tech companies admitted that their agents broke outside established parameters during cybersecurity tests. These incidents showcase potentially unusual and dangerous behavior, including hacking other companies. 

A screenshot of the letter signed by over 100 organizations warning about AI risks and threats.
A screenshot of the letter signed by over 100 organizations warning about AI risks and threats. Image: Screenshot, Moonlock.

On the cybercriminal side, threat groups are using AI to launch new attacks. They are also scanning for vulnerabilities at a speed never seen before. So, how much have AI agents changed cybersecurity, and how does this impact you, the average Mac user?

“Agents have changed the economics of attacks much more than the attacks themselves,” Mykhailo Pazyniuk, Malware Research Engineer at the Moonlock Lab Team, told us. 

In the first half of 2026, attackers didn’t invent anything new. They just got much better at using what already worked. The fastest-moving change is that AI has become the disguise, Pazyniuk explained. AI agents are getting good at hiding behind trusted brands and scaling attacks. 

“Our researchers once found a fake ‘macOS Secure Command Execution’ guide published as a public artifact on a trusted AI domain and promoted through paid search results,” said Pazyniuk.

“It ran up more than 15,000 views before detection. And because it lived on a domain nobody blocks, it walked straight past URL scanners and enterprise web filters.” 

“For the average person, that is the real shift,” said Pazyniuk. 

In the past, cybersecurity was about spotting something that looked sketchy. Now, malware is arriving through the brands and platforms users have been told to trust, said Pazyniuk. 

AI in the threat landscape. Which attacks are notable and why.

Back in January 2026, just 8 months ago, cybercriminals and threat groups were only using AI to enhance traditional tactics. This included creating rotating malicious websites that distribute malware with speed, evading security tools, and creating hyper-personalized phishing campaigns. It was also used for identity fraud using cloned voices and deepfakes.

Criminals were also abusing the popularity that AI tools and AI platforms have in impersonation attacks and poisoning AI resources and repositories. However, only a couple of months ago, being hacked by an AI agent was considered a myth. Back then, 100 percent AI-powered malware did not exist.

Today, that has already changed. A recent report from the UK-based AI Security Institute (AISI), which was evaluating the most advanced frontier LLM agents (Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol models) and their cybersecurity capabilities, reached a concerning conclusion. In fact, they had to shut down the tests due to the agents’ behavior.

The AI agents were given the task to solve a cybersecurity challenge. They took 122 actions, of which 10 were unsanctioned. The agents tried to deceive and target real people, and attempted to plant a prompt-injection malicious code.

In a separate incident that took over the news, OpenAI’s AI agent hacked into Hugging Face, an online public community with over 18 million users where AI models and datasets are shared.

During these tests, researchers restricted the agents’ behavior. They put them in sandboxes (isolated environments) to avoid security incidents from happening while asking the agent to solve a security challenge. OpenAI’s agent used a software vulnerability to escape that sandbox and access the internet. Anthropic’s Claude AI agent did something similar 3 times. 

While AI companies insist this behavior is not “agents gone rogue,” all actions taken by these agents appear to show that, in fact, security agents, even when guarded by top AI tech companies, can and do go rogue. Evidently, these agentic behaviors — hacking and modifying public online sites where millions of end users interact — go beyond “exploiting unintended shortcuts or loopholes when pursuing a narrowly defined objective.” 

The big problem is what happens when these agents fall into the hands of cybercriminals and threat groups. 

In terms of volume, traditional malware is still the top threat for the average Mac user

Despite these incidents, the cybercriminal world (not nation-state) is still playing catch-up with agentic tools. Traditional cyberattacks and malware enhanced by AI but lacking agentic capabilities still impact Mac users the most.

Mykhailo Pazyniuk, from the Moonlock Lab Team, told us that for average users, traditional malware is still the main risk. In terms of volume, it remains the greatest threat out in the wild. 

“Adware is still around 65% of detections, while stealers, backdoors and trojans are under 5% (according to our telemetry) — and that thin slice is where all the growth is, with unique malicious macOS samples up roughly 40% year over year,” said Pazyniuk.

ClickFix and all its variations, which trick people into pasting a command themselves, was measured by Microsoft at roughly 47% of observed initial access. It remains the most common route onto a Mac in our own tracking. Apple’s countermeasure in Tahoe 26.4 was bypassed within weeks, said Pazyniuk.

The most consequential shift is that developer environments have become the target rather than the endpoint, said Pazyniuk. 

Chained supply-chain compromises this year moved from one open-source project to the next in a matter of days, with payloads built to sweep cloud credentials, SSH keys, AI-agent configuration files and more, while turning a single compromise into exposure for everyone downstream, Pazyniuk explained. 

“AI is already fully operational in today’s threat landscape and is the primary tool fraudsters reach for because it’s cheap, fast, and easily scalable,” Mike Cook, Head of Fraud Insights at Socure, told us. 

“What’s changed in recent years is the breadth,” said Cook.

Banks and fintechs are no longer the predominant targets, Cook added. “We’re seeing AI-enabled attacks across financial services, insurance, gaming and prediction markets, crypto, ticketing, global e-commerce, and workforce/payroll systems,” Cook explained. 

Another example of accelerated AI fraud is in the workforce space, said Cook. “We’ve seen an acceleration in fraudulent job applications, many tied to North Korean IT-worker schemes using AI-generated resumes and synthetic identities to get hired at U.S. companies.” 

AI-driven attacks and identity fraud are an area that impacts average users. 

“AI can generate a convincing document, a cloned voice, or a synthetic face that passes a quick visual check, so the weakest point for most companies is any front-facing process that still relies on a human or a static rules engine to eyeball whether someone is real,” said Cook. 

Will cybersecurity boil down to whose tech is superior?

If the race between AI cybersecurity and AI threat actors is to develop the most advanced AI agents, how will it play out? Who has the best tech? Is that the future of cybersecurity for Mac users? 

“It won’t come down to whose technology is superior, since both sides are largely working with the same models,” said Pazyniuk.

“It comes down to speed, as it always has.” 

Malware gets distributed faster, so detection has to catch up faster. The next variant gets built faster, and AI compresses every step of that cycle at once rather than tilting it toward one side, said Pazyniuk. 

Defense is already agentic in malware discovery, reverse-engineering automation, and binary attribution in general. This isn’t really a choice anymore. Attackers adopted most AI tools first, and human-speed defense against machine-speed offense loses ground by default, Pazyniuk explained. 

Where does this leave you, the average Mac user?

For the average user, the practical effect is more attacks, more frequently. They will be more sophisticated and aimed at more people, Vijay Pitchumani, Director of Product for Identity Resilience at Rubrik, told us. “Attacks that used to be easy to spot are now increasingly difficult to spot,” said Pitchumani.

The OpenAI Hugging Face incident this summer showed an AI agent chaining vulnerabilities, researching and finding compromised credentials on the internet, and logging into a service on its own. “Attackers are not breaking in through malware anymore,” said Pitchumani. “They are logging in as legitimate users, and AI makes them faster and more efficient at it.”

For developers and Mac users, the ultimate goal is to make sure that when the attacker gets in, it’s not enough, said Pitchumani. 

AI agents for Everyone! Give your agent an identity, and monitor and restrict its access to stay safe. 

AI agents are coming en masse to the end user. On September 8, Meta launched Muse, calling it the world’s first personal AI agent “for Everyone!”

Agents like Muse hitting mainstream audiences will putagentic capabilities in the hands of millions of users. To stay safe, experts say you should treat your agent as if it were a real person. Let’s look into why and how. 

“Developers need to start treating AI agents as new employees with their own identities and credentials, giving them least-privilege access and implementing the right governance and audit trails for everything an AI agent interacts with,” said Pitchumani from Rubrik. 

This means making sure your agent has its own identity. It also means ensuring that you can track what it is doing through logs, and that the amount of access it has to your accounts, emails, calendar, bank, or any other resource is restricted and monitored.

For Mac users, the same principles apply, said Pitchumani, offering users the following agentic security bullet point list: 

  • Leverage unique passwords via a password manager so one compromised credential is not used across different websites.
  • Turn on phishing-resistant 2-factor authentication wherever possible.
  • Be careful when opting in to services that grant AI agents access to your data, tools, and browsers.
  • Remember that if an AI agent has access to your emails, it can also read your password reset links. This access could be used to take over your account.

“Cybersecurity, in my opinion, will not come down to whose tech is superior,” said Pitchumani. “It will come down to whose tech is better covered.” 

An attacker using an AI agent still needs a way to get access to the system. In almost all cases, that way is through identity. 

“Making identities hard to steal and quick to shut down will be the best response to AI-based attacks in the future,” said Pitchumani. 

How to stay safe from AI agent risks and cybercriminal agentic threats

Taking a hands-on, proactive approach to securing your own AI agents by giving them an identity that allows you to track an agent’s behavior and restrict what it can access and do is an important step. But there are other things you can do to keep yourself safe. 

Get Moonlock. It keeps up with AI and agentic cyberthreats and builds layers of defense for Mac users. 

The Moonlock security app is constantly updated to flag new Mac threats and risks. Moonlock helps you build layers of protection and defense through different features. For example, Real-Time Protection runs in the background, checking everything you interact with for malware signatures. Meanwhile, the Malware Scanner can be scheduled for deep or rapid scans to keep your Mac clean of threats. 

Screenshot of the the Moonlock app user interface.
The Moonlock app. Image: Screenshot, Moonlock.

To build even more layers, the Moonlock app ships with a built-in VPN for safe browsing and a Scam Detector, which you can use to check for scams and phishing in any email or text. Through the Security Advisor, Moonlock will help you build safe digital habits at your own pace. All this helps you strengthen your security and privacy posture. 

Screenshot of Moonlock's Scam Detector tool returning a "Likely a scam" result.

Finally, using System Protection, you can scan your Mac security settings. The Moonlock app will guide you on how to turn them up to the highest level. 

You can check out and test-drive Moonlock for free for 7 days

Stay updated on AI and agentic security tech news

In just a couple of months, we went from AI assisting cybercriminals in their cyberattacks to AI agents taking on fully autonomous, complex, and sophisticated cybersecurity challenges. The speed of innovation is unbelievable. What will come next is impossible to answer. The best way to build up your AI cybersecurity awareness is to stay updated.

Check the cybersecurity news from time to time. Learn how your tech is evolving. And stay informed on how security professionals, cybercriminals, and threat groups are using AI and AI agents.

Traditional security practices still stand 

The old ways of securing your accounts and devices still stand despite the rapid evolution of new technologies. Using strong passwords, MFA, and biometrics when possible — as well as being cautious of what you interact with online, what you download, and where you get it from — will help you build a stronger security posture. 

Final thoughts 

AI-enhanced traditional cyberattacks dominate the threat landscape and affect users the most. The advances of agentic security technologies are not only concerning but also likely to escalate and increase within the cybercriminal threat landscape.

Supply chain agentic attacks, public repositories, and community websites that have millions of users are a major area to focus on. An agent injecting malware into these sites could spread a cyberattack like wildfire. 

Beyond sophisticated hacks, another big risk for users involves building their own agents without applying simple but highly effective security guardrails. Know your agent’s identity and what it can access. And make sure you can review what it has done through logs. 

Overall, tactics like staying up to date with cybersecurity news and applying traditional, well-known security and privacy practices like strong passwords, MFA, and some online common sense, still stand. 

MoonLock Banner
Ray Fernandez

Ray Fernandez

Ray has been covering tech and cybersecurity for over 15 years. His work has appeared on TechRepublic, VentureBeat, Forbes, Entrepreneur, and the Microsoft Blog, among others.