When AI Agents Run the Attack: One Endpoint to Full Server Takeover

An attacker gained access to a critical server in less than 24 hours through an exposed, unauthenticated application feature. The unusual part wasn't the entry point. It was who, or what, was behind the keyboard. ReliaQuest Threat Research assesses with high confidence that this attack was driven primarily by AI agents, likely the first of its kind we've seen. The agents ran commands, hit errors, corrected them, and kept executing without a human at the keyboard.
Join us for a breakdown of the infrastructure behind the attack, the evidence that exposed AI-driven execution, and the practical steps defenders can take to detect and contain adversaries operating at machine speed.
What you’ll learn:
The signs of machine-driven execution, including timing patterns, job naming, output formatting, and self-correction.
How one exposed job-submission endpoint created a path from code execution to SYSTEM access.
What changes when attacker speed is no longer limited by human operator time — and how defenses must adapt.
Attendees of this live webinar are eligible for CPE credit.
Explore Other Webinars