Google Threat Intelligence tracks evolving adversarial AI tactics and supply chain risks
The Google Threat Intelligence Group (GTIG) reports a significant evolution in adversarial AI, as threat actors shift from basic prompting to agentic AI workflows and AI-enabled automation. This transition dramatically reduces human-in-the-loop latency, compressing the window for defenders to respond to attacks. Adversaries are increasingly targeting proprietary AI models, source code, and cloud environments, while also exploiting AI-assisted coding tools to compromise open-source software supply chains. The report details key Q2 2026 trends, including activities by threat actors like UNC6780.
- →Adversaries transition to agentic AI workflows and automation
- →Expanding software supply chain risks through AI-assisted coding
- →Increased targeting of proprietary AI intellectual property
- →Multi-stage lifecycle augmentation and illicit account procurement
- →UNC6780 demonstrates severe open-source software supply chain exploitation
Notes (5) ›
- Adversaries transition to agentic AI workflows and automation
GTIG observes threat actors moving from basic AI prompting to agentic AI workflows and AI-enabled automation. This shift significantly reduces human-in-the-loop latency, shrinking the time available for defenders to detect and respond to attacks, with one credential harvesting campaign executed in under six hours.
- Expanding software supply chain risks through AI-assisted coding
The integration of AI-assisted coding tools and open-source software increases operational risks, with threat actors actively targeting developers, AI coding assistants, and large language model (LLM) security scanning tools. GTIG tracked examples where malicious open-source AI resources were attempted to be downloaded, or malicious dependencies were incorporated into legitimate projects.
- Increased targeting of proprietary AI intellectual property
Adversaries are increasingly targeting proprietary AI models, code, prompts, and research across various sectors, including healthcare, government, and media. Threat actors exfiltrate API credentials and co-opt victim cloud environments to sustain unauthorized AI workloads, highlighting these assets as high-value targets for espionage and resource theft.
- Multi-stage lifecycle augmentation and illicit account procurement
State-sponsored and cybercrime groups use AI capabilities as force multipliers across the entire attack lifecycle, from reconnaissance and social engineering to custom malware obfuscation. Adversaries also circumvent AI access costs by stealing developer credentials, purchasing compromised AI platform accounts, and hijacking enterprise cloud infrastructure for high-performance compute workloads.
- UNC6780 demonstrates severe open-source software supply chain exploitation
The financially motivated threat actor UNC6780 (TeamPCP) illustrates severe exploitation of AI and the open-source supply chain. Since March 2026, UNC6780 has conducted large-scale compromises of ecosystems like PyPI, npm, and Docker Hub, deploying credential stealers and creating malicious GitHub Actions workflows for proprietary AI repositories.
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai/
Related releases
- Google Cloud Introduces Data Agent Kit for Agentic Data Analysis in IDEs Google Cloud Blog ·
- How KDDI Optimized Its Buffmee RAG App With Google's AI Evaluation and ADK Google Cloud Blog ·
- Looker 26.16 Rolls Out with Semantic Search GA, Admin Assistant Preview, and Bug Fixes Google Cloud release notes ·
- Terraform Provider for Google Cloud v7.46.1 Released Terraform Google Provider Releases ·
- Google Cloud Storage Introduces Dynamic Batch Operations Google Cloud release notes ·
- BigQuery Conversational Analytics Adds Market Basket Analysis Support Google Cloud release notes ·