gcp Google Cloud Blog ·

Google Threat Intelligence tracks evolving adversarial AI tactics and supply chain risks

blogaiazuregcpsecurity-advisoryengineerhealthcarefinancemediaeducationgovernmentenergygcp-bigquerygcp-cloud-run
announcement

The Google Threat Intelligence Group (GTIG) reports a significant evolution in adversarial AI, as threat actors shift from basic prompting to agentic AI workflows and AI-enabled automation. This transition dramatically reduces human-in-the-loop latency, compressing the window for defenders to respond to attacks. Adversaries are increasingly targeting proprietary AI models, source code, and cloud environments, while also exploiting AI-assisted coding tools to compromise open-source software supply chains. The report details key Q2 2026 trends, including activities by threat actors like UNC6780.

  • Adversaries transition to agentic AI workflows and automation
  • Expanding software supply chain risks through AI-assisted coding
  • Increased targeting of proprietary AI intellectual property
  • Multi-stage lifecycle augmentation and illicit account procurement
  • UNC6780 demonstrates severe open-source software supply chain exploitation
Notes (5)
  • Adversaries transition to agentic AI workflows and automation

    GTIG observes threat actors moving from basic AI prompting to agentic AI workflows and AI-enabled automation. This shift significantly reduces human-in-the-loop latency, shrinking the time available for defenders to detect and respond to attacks, with one credential harvesting campaign executed in under six hours.

  • Expanding software supply chain risks through AI-assisted coding

    The integration of AI-assisted coding tools and open-source software increases operational risks, with threat actors actively targeting developers, AI coding assistants, and large language model (LLM) security scanning tools. GTIG tracked examples where malicious open-source AI resources were attempted to be downloaded, or malicious dependencies were incorporated into legitimate projects.

  • Increased targeting of proprietary AI intellectual property

    Adversaries are increasingly targeting proprietary AI models, code, prompts, and research across various sectors, including healthcare, government, and media. Threat actors exfiltrate API credentials and co-opt victim cloud environments to sustain unauthorized AI workloads, highlighting these assets as high-value targets for espionage and resource theft.

  • Multi-stage lifecycle augmentation and illicit account procurement

    State-sponsored and cybercrime groups use AI capabilities as force multipliers across the entire attack lifecycle, from reconnaissance and social engineering to custom malware obfuscation. Adversaries also circumvent AI access costs by stealing developer credentials, purchasing compromised AI platform accounts, and hijacking enterprise cloud infrastructure for high-performance compute workloads.

  • UNC6780 demonstrates severe open-source software supply chain exploitation

    The financially motivated threat actor UNC6780 (TeamPCP) illustrates severe exploitation of AI and the open-source supply chain. Since March 2026, UNC6780 has conducted large-scale compromises of ecosystems like PyPI, npm, and Docker Hub, deploying credential stealers and creating malicious GitHub Actions workflows for proprietary AI repositories.

Read the original announcement →

https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai/

Related releases