THREAT OPS › Threat News › When AI Workloads Start Acting Like Users
When AI Workloads Start Acting Like Users
At 2:14 AM, a SIEM alert surfaces. An internal AI research agent with access to project data and approved SaaS credentials has initiated outbound HTTPS connections to eleven previously unobserved external domains in six minutes.Nothing looks obviously malicious. The traffic is encrypted, volumes are modest, and the workload presents valid credentials throughout. It retrieved content from a third-p
MITRE ATT&CK techniques
- CredentialsT1589.001