Companies are eager to put AI agents to work writing code, managing tasks, and fixing problems without someone supervising every action. Unfortunately, attackers can use those same capabilities to work through the problems standing between them and a compromised server.
A new ReliaQuest investigation describes an incident in which an attacker gained full administrative control of a server in under 24 hours. Researchers assess with high confidence that agents driven by large language models carried out substantial portions of the attack, which involved hundreds of commands.
The initial opening was an application feature that accepted job submissions over the internet without requiring a login. The attacker used it to execute code, retrieve information through error messages, and recover plaintext database credentials from configuration files.
Those credentials provided SQL Server administrator access, allowing the attacker to enable operating-system command execution. Public privilege-escalation tools then helped the attacker obtain SYSTEM access on Windows, extract stored credential material, and create local administrator accounts. No zero-day or new malware was required.
The AI connection goes beyond suspiciously fast typing. Researchers found a live dashboard for Cairn, an open-source AI agent orchestration platform, on the same IP address that initiated the attack. Command records also showed repeated corrections, with revised payloads addressing errors returned by previous attempts.
There are limits to what the evidence establishes, however. ReliaQuest could not determine which model powered the activity, how many agents participated, or how often a human approved individual actions. The report therefore supports an assessment of substantial agent involvement, while leaving the precise division of work unresolved.
That makes the incident more useful to examine than a vague warning about AI becoming dangerous. The practical concern is that software capable of reading an error and trying another approach can reduce the amount of attention an attacker needs to spend on each target. A failed command becomes another problem for the agent to work through.
For businesses, that could put more pressure on security teams already juggling alerts and investigations. An attacker who spends less time personally troubleshooting one intrusion may have more capacity to pursue others, although this report does not establish how many targets this particular operation handled.
The investigation also exposes a visibility problem. Early malicious activity ran inside the existing application process without creating child processes, and application job history survived the attacker’s cleanup. Organizations that collect endpoint alerts but overlook application records could miss evidence needed to understand how an intrusion unfolded.
I find the ordinary nature of the opening particularly troubling. An exposed management feature and credentials with excessive privileges gave the attacker a path forward. AI helped make that path easier to navigate, but the underlying weaknesses were familiar security failures.
Buying another AI security product will not excuse leaving those basics unattended. Authentication, restricted access, properly protected credentials, and useful application logs deserve attention before a company hands more work to autonomous software. This incident gives administrators a concrete reason to check them now.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz


