By Josh Lemos, CISO, at GitLab
With Anthropic recently catching the first reported AI cyber espionage campaign, the AI landscape continues to transform at a blistering pace. Over the past year, I hypothesized that LLMs gave defenders an asymmetric advantage, but that power balance has shifted. The emergence of agentic AI and the development of offensive infrastructure have created a proven path for threat actors to operationalize agentic tool chains on a mass scale. Right now, threat actors have the upper hand.
This isn’t surprising. The work of the XBOW team and OpenAI’s Aardvark, among others, demonstrates how skilled offensive operators training purpose-built threat-hunting agents can outperform individual researchers. Similar capabilities are available to threat actors. They now have a clear roadmap for using AI to execute multi-stage attacks with complete autonomy, no longer constrained by human-in-the-loop limitations.
Left unchecked, these kinds of agentic attack chains will pose significant problems for security teams. However, the same convergence of technical capabilities and processes that attackers will use can also be employed by security teams to strengthen their defenses.
More vulnerabilities are now exploits
AI agents have significantly shortened the time between vulnerability discovery and exploitation. A 2024 research paper showed how GPT-4, when provided with CVE descriptions, could autonomously exploit real-world one-day vulnerabilities. In fact, it was able to do so successfully with 87% of the vulnerabilities tested.
More recently, Google announced that its Big Sleep research has found numerous zero-day vulnerabilities in open-source projects. A collaboration between DeepMind and Project Zero, Big Sleep included a multi-phase set of agents designed to discover software vulnerabilities and build working exploits.
While Big Sleep empowered industry security leaders to prevent those exploits from materializing, there’s no doubt that malicious actors are using the same techniques to compromise targets.
Adversaries are chaining agents
This is no longer merely theoretical. Adversaries are breaking down attack phases into separate agentic workloads and using chains of agents to execute each phase autonomously.
For example, North Korean and Chinese threat actors are now using AI at every stage of their operations, from victim profiling to data analysis and identity creation.
Anthropic’s cyber espionage report found Chinese threat actors using AI agents to perform 80-90% of attack operations independently, including identifying valuable infrastructure targets, discovering vulnerabilities, exploiting them, and harvesting credentials. Human intervention was required fewer than seven times at critical decision points. Operating at thousands of requests per second, AI agents drastically shortened the timeline and manpower required to execute the campaign.
Anthropic’s 2025 Threat Intelligence Report also revealed that AI is enabling lower-skilled threat actors to learn and execute more advanced tactics, techniques, and procedures. Cybercriminals with minimal technical expertise used Claude to develop and sell multiple ransomware variants for $400-$1,200 on internet forums. In this case, the criminals relied completely on AI to implement encryption algorithms and evasion techniques.
Thanks to AI, it’s now cheaper than ever for attackers to weaponize exploits. Agentic AI enables those attacks to become more autonomous, allowing for a greater number of threat actors to launch campaigns at scale.
These trends will likely lead to many more high-volume campaigns targeting companies’ most valuable data assets.
To counteract this threat, defenders must respond with equally agentic defenses.
Fighting agents with agents
As attackers develop agentic toolchains, internal red teams, and defensive practitioners must also scale up their own use of agentic AI. Defenders need AI agents that leverage internal system resources to provide context. They can then use agents to break down defensive tasks into separate workloads, chaining them together to identify and remediate vulnerabilities before they get exploited.
For these agents to execute effectively, they need a deep understanding of your software environment. Agentic defenses require infrastructure that delivers the right data and context to the agents you deploy. Knowledge graphs, which map relationships across entire codebases, are one tool that can provide this foundation.
When provided with knowledge graphs, agents can combine valuable institutional knowledge with historical vulnerability data and known security anti-patterns to help teams prioritize threats based on actual attack patterns rather than theoretical risks.
In addition to prevention, agentic defenses also enable resilience. Defenders can break down tasks into detection and remediation activities within the context of organizational runbooks. Agents can handle everything from identification, through investigation and containment, remediation and post-mortem, to reduce dwell time and limit damage.
These use cases represent steps that we, as defenders, can take to scale up our agentic defenses. The convergence of technical capabilities and processes gives us new tools to help combat threat actors and scale up our defensive operations. The attackers aren’t waiting to make the most of those tools. We shouldn’t either.
##
ABOUT THE AUTHOR
Josh Lemos is the Chief Information Security Officer at GitLab Inc., where he brings 20 years of experience leading information security teams to his role. He is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected, fortifying the Gitlab DevSecOps platform and ensuring the highest level of security for customers.
A talented security practitioner and technology leader, Josh is widely recognized for his strategic vision, his ability to drive growth and innovation, and his passion for building and empowering teams. He believes in technology’s potential to transform the world and the need to secure it against emerging threats. Josh has led security teams at numerous high-growth technology companies including ServiceNow, Cylance, and most recently Block (formerly known as Square).
Josh’s commitment to securing technologies to make a positive impact in the world has been a common thread throughout his career. He serves as a mentor to aspiring information security professionals, and is active in supporting organizations that promote diversity and inclusion in the technology industry. Josh holds a B.S. in Computer and Information Systems Security from the University of San Francisco.





