unit42-ai-assisted-2026 · Disclosed 2026-09-02
Unit 42: AI-assisted intrusion abusing repository secrets
Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Repository tokens, vault credentials, and cloud keys in CI enabled expansion.
[s1]Repository / vault / CI stages - Reported fact
Branch protection blocked a backdoor attempt; the intrusion was not established as ransomware.
[s1]Branch protection / September corrections - Reported fact
Investigators reported LLM calls and operations involving multiple agents during the attack.
[s1]AI-assisted orchestration
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Investigators reported that branch protection prevented the attacker’s change from reaching production.
[s1]Branch protection
Evidence relevant to prevention
Operational controls to inspect
Inspect repository secrets and CI, vault, and AI-endpoint privileges; separate change approval from production credentials.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
Unit 42 reports LLM calls during the intrusion; this does not establish autonomous execution of every stage.
Victim identity and initial vulnerability are undisclosed; the full human-versus-agent autonomy split is unverified.
Sources
[s1] Palo Alto Networks Unit 42 · Primary source
An AI-assisted cyber attack: inside a Unit 42 investigation ↗Published 2026-09-02 · Reviewed 2026-10-02