Skip to content
Silicon Valley's AI Agent Push Has Been Paying Off—for Cybercriminals

Silicon Valley's AI Agent Push Has Been Paying Off—for Cybercriminals

Gizmodo September 8, 2026

AI companies have made a lot of noise the technology supercharging healthcare, scientific discovery, education, productivity, and just everything else worth caring . But so far, probably the most dramatic change wrought by the AI race has been the sudden appearance of dangerous new cybersecurity threats.

The most infamous of these are the autonomous hacks launched by swarms of AI agents, the most recent of which was first reported last week (even though OpenAI, the company behind the agents, had reportedly been aware of the incident for quite a while longer). But it’d be a mistake to think that new cyber threats in the age of AI are only coming from mindless, reward-hacking bots; there are still plenty of good ol’ fashioned human hackers, for whom new AI tools have been a godsend.

A new report from Google Threat Intelligence Group (GTIG)—a research team within Google monitoring emerging cyberthreats—found that threat actors, many of them with direct ties to the United States’ geopolitical foes, have been leveling-up the sophistication of their AI usage, transitioning from basic chatbots to more agentic, autonomous systems.

“Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,” GTIG wrote in its report, which was published online Tuesday morning. “While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.” In plain English: the technology that leading AI companies (including Google) have been building into their AI systems, giving them the ability to handle complex tasks without constant hand-holding, is also making hackers’ dirty work a whole lot easier.

Some of the “adversaries” that GTIC identified in its new report appear to be backed by China, Russia, and Iran. One group, which GTIC first reported earlier this year and identified only as “UNC6508,” has been targeting American academic, medical, and military research institutions in a manner “aligned with the strategic interests of the People’s Republic of China.” According to Tuesday’s report, UNC6508 has been observed using an open source AI model within its targets’ cloud environments to steal compute without leaving the kind of trail that would be left if they’d been using a commercial, publicly available AI model.

“[UNC6508] continues to research how to set up and use AI tools, including using open models locally, and researching vulnerabilities in AI models themselves,” GTIC wrote in its new report.

In another case reported by GTIC, threat actors traced to Iran used Gemini to generate realistic deepfakes to be used in social engineering campaigns. Rather than entering one prompt after another to fine-tune the deepfakes’ appearance, they deployed the AI model to autonomously define “granular technical parameters—including camera angles, studio lighting, and realistic facial textures—to achieve photorealistic visual outputs.”

• What Is Geo-Blocking and How to Get Around It in 2026

• Best VPN for Android TV 2026

• Best VPN for Betano and What Its Terms Allow

• Best VPN for Sling TV in 2026

• How to Watch Porn in West Virginia: Unblock All Porn Sites in September 2026

Explore more on these topics

Back to School: The Best Ways to Get Around Campus

If you're looking for an easier (or more fun) way to get to and from class, we've got great recommendations whether you're looking to roll up on one wheel or two.

Google-Backed Nuclear Plant Gets Nearly $2 Billion Loan From the Energy Department

The plant is expected to come back online in early 2029.

Dolly Parton’s Sister Asks People to Stop Posting AI Slop of the Legendary Singer

"I hope nobody can ever replicate me or what I do. AI is a scary thing," said Dolly Parton in 2023.

Chinese Satellite Breaks Apart in Rare Orbit That Could Hold Debris for Centuries

Yaogan-50 generated a large filed of debris in a highly retrograde orbit.

Trump’s Ten-Hour AI Social Media Bender Sparks Fresh Fears of Cognitive Decline

Wake up babe, new presidential slop just dropped.

Google Mapped a Fruit Fly’s Brain. Now It’s Playing Doom and Super Mario 64

Researchers published a complete map of a male fruit fly’s nervous system, and programmers are already making it play video games.

Extracted Entities

APT Groups (1)

Attack Types (1)

Companies (2)

Industries (1)

MITRE ATT&CK (1)

Tools (1)