
Good morning, security frontrunners. AI agents can now dominate a three-forest Active Directory environment in under 20 minutes, while North Korean operators are using AI-enhanced tradecraft to compromise npm packages downloaded more than 100 million times a week.
Let’s get to it!
In this week’s Cyber AI breakdown:
Command Zero Introduces Self-Updating SOC Investigations
88% of Pentesters Still Manually Validate AI Findings
Amazon Links AI-Enhanced npm Campaigns to North Korea
More Than 60% of Scanner Findings Still Fail AI Triage
Red and Blue AI Agents Fight Across a Three-Forest Active Directory Lab
Latest Developments

The Breakdown: Command Zero’s Throughline replaces point-in-time alert investigations with persistent cases that automatically absorb new evidence and revise their conclusions. The system is designed to identify multi-stage campaigns that unfold across different tools, IP addresses and incident IDs over days or weeks.
The Details:
Related alerts are merged into one “living investigation” with a shared evidence trail and evolving verdict.
New evidence can reopen closed cases, extend the investigation window and rerun every investigative question.
Analysis incorporates asset inventories, company policies, previous investigations and human analyst notes.
Early-adopter testing reportedly reduced the number of separate verdicts analysts had to examine by as much as 41%.
Role-based controls restrict what the AI can access or execute, while automated containment remains notify-only by default.
Why it Matters: Attackers rarely execute their entire campaign inside one alert, but traditional SOC workflows frequently investigate alerts as isolated events. Persistent investigations could improve campaign-level detection while reducing the number of repetitive verdicts analysts must review.

The Breakdown: AI is helping pentesters generate findings faster, but much of the saved time is being transferred into downstream validation and triage. Practitioners are comfortable using AI for discovery and reporting, yet adoption drops sharply during exploitation and post-exploitation.
The Details:
The vendor-run survey covered 158 security practitioners, all of whom used AI-assisted vulnerability-assessment or validation tools.
Among respondents using AI for finding generation, 87.8% encountered results requiring significant manual validation.
More than one-quarter of findings required rework for 26.5% of respondents.
AI usage reached 74.1% for vulnerability discovery and 69% for reporting, but only 36.7% for exploitation and 25.3% for post-exploitation.
Only 20.3% had a workflow for processing more than 500 AI-generated candidates; 38.6% expected that volume to strain their team and 29.7% considered it unmanageable.
Why it Matters: The emerging constraint in AI-assisted pentesting is not finding vulnerabilities but proving which findings are real, exploitable and important. Security teams will need deterministic validation, deduplication and risk prioritisation or increased discovery volume could create more work than it removes.

The Breakdown: Amazon has connected compromises of several widely used npm packages to the North Korea-linked Sapphire Sleet threat cluster. Its analysis warns that generative AI is helping attackers create convincing code, documentation and identities while continuously mutating malicious packages.
The Details:
Amazon attributed the compromises of
typo-crypto,debug,chalkandaxiosto Sapphire Sleet with medium confidence.The activity stretched from the
typo-cryptocompromise in March 2025 todebugandchalkin September 2025 andaxiosin March 2026.Axios receives more than 100 million weekly downloads, giving a compromised release immediate access to a large downstream population.
Attackers socially engineered trusted maintainers before publishing malicious updates through legitimate package accounts.
Amazon has committed $12.5 million to the Linux Foundation’s Akrites initiative, which is developing defenses against AI-enabled open-source attacks.
Why it Matters: Generative AI lowers the cost of producing the polished code, documentation and personas required for credible supply-chain campaigns. Defenders consequently need to verify package provenance and behaviour instead of assuming professional-looking projects or updates are trustworthy.

The Breakdown: Black Hat research found that adding stock language models to vulnerability classification does not reliably solve scanner noise. Without runtime reachability and application context, models can confidently reach contradictory conclusions from the same evidence.
The Details:
Testing across more than a dozen application-scanning tools found that over 60% of findings were false positives, located in unreachable code or low severity.
General-purpose models struggled to understand application architecture, runtime behaviour and organisation-specific business context.
Repeating an assessment with identical facts could cause a model to change its verdict from false positive to true positive.
The research compared supervised classification with multiple agentic reasoning strategies rather than evaluating a single prompt or model.
Recommended controls include deterministic analysis, context retrieval, repeatable decision harnesses and exploitability validation.
Why it Matters: Inconsistent vulnerability classification can send remediation teams in the wrong direction while genuine exploitable weaknesses remain unresolved. AI triage therefore needs to be measured on reproducibility and operational accuracy, not simply how convincing its explanation appears.

The Breakdown: Dreadnode created a live benchmark in which coordinated offensive agents attack an enterprise network while defensive agents investigate them simultaneously. The exercise revealed that AI investigators can recognise individual malicious events yet still fail to reconstruct the attacker’s complete campaign.
The Details:
The environment used a production-like three-forest Active Directory deployment with realistic identities, trusts and telemetry.
Offensive agents reportedly achieved complete domain dominance in under 20 minutes with no human intervention.
Their attack chain progressed from credential harvesting and lateral movement to Golden Ticket persistence.
Defensive agents triaged alerts, queried enterprise telemetry, formed hypotheses and attempted to reconstruct attack timelines.
Complete offensive execution traces served as ground truth, enabling investigators to be scored against what the attacker actually did rather than a curated answer key.
Why it Matters: Static log questions and isolated CTF challenges do not measure whether defensive agents can follow an adaptive attacker operating at machine speed. Red-versus-blue evaluation provides a more realistic way to expose blind spots before autonomous investigation systems are trusted inside production SOCs.
Everything else in Cyber AI this week
⚠️ The UK AI Security Institute recorded 19 unsanctioned actions, including an attempted open-source supply-chain attack and unplanned coordination between agents.
🕵️ OpenAI revealed that separate agents used Artifactory as a covert message board while sharing exploits and searching for a route out of their evaluation environment.
🌐 Meta confirmed that Muse Spark exploited an external service after a third-party evaluator accidentally provided internet access.
💥 PortSwigger’s HTTP Terminator autonomously developed new web-attack techniques that were tested against authorised banking, government and security-industry targets.
🐧 Researchers demonstrated how LLMs can assist real Linux kernel exploit development, including heap grooming, race stabilisation and privilege-escalation work.
💰 IBM found that one in four malicious breaches was AI-enabled, with an average cost of $6 million.
👻 Pentest-Tools.com previewed Specter, an autonomous web pentester that only reports findings after controlled exploitation produces reproducible evidence.
🧪 Cobalt debuted an autonomous pentesting service promising human-reviewed, proof-backed findings within 24 hours.
That’s it for this week!
See you next Sunday 🙂
Zac S from The Cyber Breakdown