See the write-up below; seems like the best example yet of attackers scaling cyber operations with agents
* financially motivated; stole ~600k unexpired credit cards
* attack system coordinated a few harnesses, used inference via openrouter
* campaign was observed to use glm 5.2, deepseek v4 pro, deepseek v4.1 flash, and opus 4.6 (opus wasn't as well guardrailed as later models)
* attackers used minimal human nudging and input to keep the agents going, vibe-coding style
* agents mostly exploited non-sexy web app vulns
* agents showed impressive automation of human pentester intelligence; "each attack path was chosen by the harness in real time through extensive probing and exploitation attempts, resulting in dynamic and mostly different TTPs"
We have discovered a massive, ongoing criminal exploitation campaign using Cairn, an autonomous penetration-testing harness, and other AI agents to target hundreds of organizations and successfully breach and impact tens of them (at least). The image below shows just a few days of activity, with up to 25 organizations being attacked simultaneously at the peak.
our intreim report:
gambit.security/blog-posts/a…