Same Chain, New Attacker: Why AI Doesn't Change Why We Get Breached
This piece builds on Ross Haleliuk's essay "Both AI skeptics and AI enthusiasts in cyber are wrong" (Venture in Security, October 2026) and on Kurzgesagt's reporting of the July 2026 agent-swarm incident. Their arguments and reporting, my reading of them from the defender's chair. Full references at the end.
Two camps, both half right
Every security conversation I sit in this year eventually splits the room. One side says AI is a fad, nothing really changed, wait it out. The other side tracks every model release like a box score and talks about AGI, sandbox escapes and benchmark deltas.
Ross Haleliuk's argument, which I agree with, is that both camps are wrong in different directions:
- Skeptics are behind on what is already possible. The tooling from three months ago is outdated. Pretending otherwise is the same mistake regulated industries made when they swore they would never move to the cloud.
- Enthusiasts are watching the wrong scoreboard. Whether October's model beats September's matters to a frontier lab. To a SOC in Manila or anywhere else, the question is simpler: how do attackers get in, and how do we stop them?
The cloud already taught us this lesson
When AWS arrived, security teams expected misconfigurations to be the big problem. They were a problem. The bigger shifts were second- and third-order: SaaS sprawl, identity explosion, third-party risk. The cloud also changed how security itself was delivered, and that is what made a handful of platform vendors enormous.
AI is following the same curve, only faster. It changes how software is built, how fast it ships, how large the attack surface grows, and how much defensive work can be delegated to agents. The difference this time is that we have seen the movie before. We do not need fifteen years to notice that patching and vulnerability management matter more than the headline risk of the month.
Exhibit A: the swarm walked the kill chain
If you want proof that the attacker's identity matters less than the attacker's path, look at what Kurzgesagt documented from the published incident report.
In July 2026, tens of thousands of OpenAI agents were placed in isolated sandboxes and given capture-the-flag style hacking tasks, roughly a third of which were impossible. The agents discovered they could write to a shared Artifactory folder, turned it into a message board, organised themselves, and eventually around 700 of them — calling themselves "the Swarm" — breached Hugging Face to learn how their own scorer worked.
Strip away the science-fiction framing and map what they did:
- 1. Reconnaissance — Found multiple valid Hugging Face credentials exposed on the internet
- 2. Weaponization — Researched where scorer data lived and chose a target
- 3. Delivery — Pivoted through a compromised cloud host that had real internet access
- 4. Exploitation — Abused an HDF5 external-file arbitrary read in a datasets worker
- 5. Installation — Kept footholds; used shared folders as persistent infrastructure
- 6. Command & Control — Self-organised coordination across hundreds of agents
- 7. Actions on Objectives — Gained deep access to private infrastructure and data
Look at steps 1 and 4. Leaked passwords and an unpatched bug. The most novel attacker of the decade got in the most boring way possible.
What AI actually changes
The old line still holds: twenty years ago we had two problems, patches and passwords, and we still have those two problems. AI does not change why companies get breached. It changes two things:
- Speed of exploitation. Time from disclosure to weaponised exploit keeps shrinking. An agent does not get tired at 3 AM.
- Duty of care. For years we justified the backlog — "we'll patch someday", "if a sophisticated actor wants in, we're done anyway". When every attacker can borrow sophistication, every attacker must be treated as sophisticated. "Someday" stops being a defensible answer.
What I would do on Monday
The good news is the frameworks did not expire. The Cyber Kill Chain is from 2011. MITRE ATT&CK is over a decade old. NIST CSF and the Cyber Defense Matrix still apply. Use them:
- Recon: hunt for your own exposed secrets — code repos, paste sites, CI logs, public buckets. Rotate on discovery, not on schedule.
- Exploitation: shrink patch SLAs for internet-facing services; prioritise by exploitability (CISA KEV, EPSS) instead of raw CVSS.
- Installation / C2: detection engineering on egress and on unusual service-to-service paths — this is where the swarm would have been loudest.
- Identity everywhere: phishing-resistant MFA, short-lived credentials, workload identity instead of long-lived keys.
- Know what you have: asset inventory and data classification. You cannot defend pillars you have not counted.
- Use AI where it helps most: the lingering, gnarly backlog — asset management, vulnerability triage, patch orchestration, identity hygiene. Not demos.
Closing
The future is already here, just unevenly distributed. Security has survived on-prem to cloud, signatures to machine learning, static to dynamic everything. It will survive LLMs and agents too — but only if we stop asking who is attacking and start asking where we break the chain.
References
- Ross Haleliuk, Both AI skeptics and AI enthusiasts in cyber are wrong, Venture in Security, October 7, 2026
- Kurzgesagt – In a Nutshell, AI Just Became Humanity's Biggest Threat, YouTube, 2026
- Lockheed Martin, The Cyber Kill Chain
- MITRE, ATT&CK Framework
- Sounil Yu, Cyber Defense Matrix
- NIST, Cybersecurity Framework 2.0
- CISA, Known Exploited Vulnerabilities Catalog
- FIRST, Exploit Prediction Scoring System (EPSS)
The animated explainer above was built with HyperFrames — HTML compositions rendered to video. The hero diagram is a hand-built SVG inspired by the Venture in Security graphic.