THREATOPS
THREAT OPSThreat News › When AI Workloads Start Acting Like Users

When AI Workloads Start Acting Like Users

lowzscaler_threatlabzPublished 2026-09-09

At 2:14 AM, a SIEM alert surfaces. An internal AI research agent with access to project data and approved SaaS credentials has initiated outbound HTTPS connections to eleven previously unobserved external domains in six minutes.Nothing looks obviously malicious. The traffic is encrypted, volumes are modest, and the workload presents valid credentials throughout. It retrieved content from a third-p

MITRE ATT&CK techniques

Original source: https://www.zscaler.com/blogs/cxo-insights/when-ai-workloads-start-acting-users