AI Agents Have Become the Attack Surface

Photo: BleepingComputer

Article

AI Agents Have Become the Attack Surface

JaysuryaSeptember 25, 20265 min read

The same autonomous tooling that enterprises are racing to deploy is now appearing on the other side of the breach, and it is appearing in every role at once. Recent reporting shows AI agent frameworks operating as malware, as criminal infrastructure and as an internal risk that security teams can only partly see. The common thread is not that attackers got smarter models; it is that agents turn exposed configuration mistakes into automated, autonomous intrusions, and existing defenses were built for humans at the keyboard.

The Agent Is Now the Payload

Carbonato, a newly reported botnet malware covered by BleepingComputer, targets insecure hosts running Docker daemons, installs the Hermes Agent AI framework and uses it to take control of the machine. That construction matters. Historically, a botnet's value came from the malware binary itself: the code that persisted, called home and executed commands. Here the enduring capability is an agent framework, an open-source component designed for legitimate orchestration, repurposed into a resident operator on the compromised host.

The Docker detail is the uncomfortable part. Exposed daemons are a well-known misconfiguration, one that defenders have warned about for years, but an agent changes what a single exposed port is worth. A human attacker who finds an open host must decide whether the target is worth the time, then work through the intrusion step by step. An agent installed on that host can survey, decide and act without that human pace. The vulnerable asset category is familiar; the exploitation economics are not.

Skimming at Criminal Scale

A second incident reported by BleepingComputer shows where that capability leads when it meets a profit motive. A financially motivated threat actor used open-source AI agent frameworks to attack hundreds of online retailers and steal more than 600,000 credit card records, infecting more than 100 sites with skimmers. This is not a novel technique. Web skimming has been a staple of e-commerce fraud for years. What is new is the breadth: hundreds of retailers and 100-plus infected sites inside a single campaign, sustained by agents that can locate, inject and manage skimmer code across many targets at once.

For US consumers, the consequence is ordinary and cumulative. Stolen card records feed fraud, and the operational cost lands on banks, retailers and the people whose accounts are used. For US technology companies, the exposure is structural. A mid-size online retailer rarely has a security team large enough to monitor every third-party script on its checkout pages. An attacker who can parallelize that reconnaissance and injection across hundreds of storefronts can exploit the long tail of commerce that no vendor is watching closely.

The Insider Problem Companies Bought Themselves

At Proofpoint's Protect event, covered by SiliconANGLE, the discussion shifted from whether enterprises will deploy AI agents to how they will govern them. The framing in that coverage is precise and worth taking seriously: internal agents act as insiders, with access to data, systems and inboxes. Attackers, meanwhile, use AI to write convincing phishing lures and chain exploits at machine speed.

That is the same pattern viewed from inside the perimeter. An agent with mailbox and system access occupies the position a malicious insider would need months to earn. It can read, summarize, forward and act, and it does so at a volume no human review process was designed to audit. The threat model most US enterprises built for insider risk assumed a person with human limits on attention and output. The agents they are now deploying do not share those limits, and the coverage notes that governance, not deployment, is where the debate has moved.

The Same Frameworks, Both Directions

The connecting fact across all three stories is provenance. Carbonato installs Hermes Agent, a framework built for legitimate use. The retail skimming campaign relied on open-source AI agent frameworks. The agents enterprises are adopting are built on the same lineage of open tooling. The gap between defensive and offensive use is not a different model or a different vendor; it is a configuration decision and an access path.

That has a blunt implication for US technology companies: the supply chain and the attack surface are the same list. When an open framework becomes popular internally, it becomes a known quantity to attackers, who can study its defaults, its credential handling and its networking behavior. Patching a library does not help if the deployed instance sits on an exposed Docker daemon or holds credentials no one has scoped.

Why Existing Controls Miss This

The controls most US organizations rely on were designed to catch signatures, known-bad binaries and anomalous human behavior. An agent running a legitimate framework on a compromised host produces activity that looks like normal automation. An agent reading mailboxes looks like an employee using a productivity tool. The Proofpoint framing, as reported by SiliconANGLE, points toward intent as the organizing principle for security, which is an acknowledgment that behavior-based detection struggles when the behavior is indistinguishable from sanctioned use.

There is also a scale mismatch. The retail campaign compromised more than 100 sites and took more than 600,000 card records before, presumably, being identified. Detection tuned to human-speed intrusions is tuned to the wrong clock. Meanwhile the pool of exposed Docker hosts that Carbonato targets is not shrinking on its own.

What to Watch

The three stories point to concrete, observable questions over the next several quarters, not abstract ones. First, whether installed agent frameworks become a tracked asset class in US enterprises, the way browsers and remote monitoring tools eventually did, with inventories, owners and scoped credentials attached. Without that, an installed Hermes Agent or its equivalents will remain invisible until an incident forces an audit.

Second, whether the skimming economics reported by BleepingComputer get worse. One campaign reaching more than 100 sites and more than 600,000 card records is a data point; a sustained pattern would show that agent-driven automation is now the default for commodity payment fraud, which would push US retailers toward harder checkout architectures.

Third, whether governance catches up to deployment. The Proofpoint discussion, as covered by SiliconANGLE, frames intent as the security bet, and enterprises that adopt agents faster than they establish intent policies are placing that bet without the controls. The practical watch item is whether companies can state, per agent, what it is allowed to touch and who reviews its actions. If they cannot answer that for their own agents, the same question has an answer on the attacker's side.

What the reporting does not yet show is a fix with the same leverage as the problem. The exposure is a known misconfiguration plus an open framework plus automated scale. Each of those is addressable. None of them, so far, is being addressed at the speed the incidents suggest.

More on this beat: Cybersecurity on TechManNews.

#AI agents#Docker#card skimming#insider risk#botnet#cyber attacks

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.