
Findings and evidence
Google Threat Intelligence Group reports a shift toward AI-assisted automation in observed campaigns and growing interest in model assets, source code and API credentials. The publication separates several patterns drawn from its recent investigations.
Why it matters
Add AI-service identities and assets to the incident evidence plan. Correlate access, configuration changes and usage records, then verify whether suspicious activity actually crossed an authorization boundary.
Scope and limits
The report describes activity visible to GTIG. Observed use of an AI tool does not, by itself, prove autonomy, causation or a universally faster attack.
Primary source
Google / Mandiant: original publication. Source published 2026-09-08. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.