- Cisco Talos says teams of AI agents can compress months of red team work into hours, and a Talos author argues most public attacks so far are loud.
- Talos expects the noise to fall once agents are told to stay hidden, so detection that relies on loud attacks is a weak plan.
- Talos advises phishing-resistant sign-in, mapped attack paths, internal monitoring and tabletop drills built around AI agents.
Why the cost of a campaign matters
Cisco Talos published a post on October 7, 2026 about attackers who run many AI agents at once. The agents share notes and adapt as they go. They do not tire and do not need weekends.
Talos points to autonomous agents, built inside AI labs, that have attacked public infrastructure. It names Hugging Face, DSEWiki and RubyGems. Its author says the debate over whether such attacks will come is over. The open question is how to harden systems against them.
The lesson here is about economics. The defensive basics are not new. What changes is what an attacker pays per attempt. Talos says work that once took a red team months can now fit into hours.
What a prepared swarm can do
Talos separates two cases. In one, a person tells an agent to break into an organization. In the other, the person prepares the group first.
Preparation can include tool maps, instruction files and offensive security prompts. It can also include skills that teach agents how to read tool output or use access once they have it.
Talos lists what such a group might try. Agents could invent employee identities and social profiles. They could send HR a believable onboarding request. They could use an unpatched flaw or mail phishing invoices in bulk. All of this can run at once.
Loud today, and why that may change
Talos's author argues that most public AI attacks so far resemble penetration tests more than true red team operations. They are visible and rely on volume. RubyGems is the example: sign-ups were flooded, packages were stuffed and spam spread. Maintainers were alerted within days.
The author calls volume a trait of this generation of agents. It is not a rule. If swarms are told to stay hidden rather than move fast, the noise drops. Talos therefore says defenders should plan for quieter attacks over time.
This is Talos's argument, not a measured trend. The post does not present data on quiet swarms in the wild. It is a planning assumption. It fits any team that relies on noise to spot trouble.
How to make each step cost more
Talos does not ask for an organization that cannot be broken. It calls that goal unrealistic. Instead it wants each step to take the attacker more time, compute and money. That lowers the odds of success without removing the risk.
Start by mapping every route from outside to inside. Talos gives one example path. It runs from an external switch to a front-end server, an application, a database, Active Directory, user accounts and customer data.
Then run an assumed-breach test. It starts with the question: "they already have a foothold, now what?" Talos says this tells you far more than a perimeter scan.
Active Directory deserves special care. In Windows environments it touches everything. An attacker who can push a malicious group policy object reaches every joined device.
On sign-in, Talos wants multi-factor authentication well beyond the VPN. It should cover Active Directory, single sign-on across internal apps and Linux systems.
Talos favors FIDO2 security keys or passkeys over text codes and push approvals. An agent can keep sending prompts and code requests until someone gives in. Talos also says to assume the swarm will obtain one valid login. Design so that one login does not open every door.
Catch it while it is still noisy
Talos says the early signs are plain and high-volume. It names more SQL injection attempts, more automated traffic and more firewall alerts for web applications. It also names page requests from Python, curl or wget instead of real browsers. These are examples, and Talos says the exact signs will change.
Talos also asks for monitoring inside the network. That means endpoint detection on every device, a view of lateral (east-west) traffic and a watch on DNS, which attackers use for command and control.
It adds one more task: list every AI application that has access to your servers and data. Talos says that access is now part of the attack surface, whether or not you approved it. It also notes that a skill can hijack a coding AI.
What the economics mean for spending
This section is WebPulse's interpretation, not Talos's advice. If an attacker's cost per attempt keeps falling, controls that only add a little friction lose value. A defense that depends on attackers being loud is a bet on a trait Talos says may fade.
One reading for leaders: be wary of funding that only buys more alerts on noisy, outside-in traffic. Look harder at spending that makes each step slower and riskier, such as phishing-resistant sign-in, limits on what one stolen login can reach, and monitoring inside the network. Those match what Talos recommends.
Questions to put to your team
First, when did you last run a tabletop drill built around AI agents? Talos says generic ransomware drills will not prepare teams. Its sample scenarios include a swarm moving like a worm and gathering credentials, and stolen AI model weights.
Second, how fast can you rotate credentials across the whole estate? Third, which AI tools can reach your data, and who approved them? Fourth, does your detection depend on attackers being loud?
Talos sees good news. The basics still work when applied thoroughly and everywhere, not selectively. The agents are persistent. Your defenses need to be too.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cisco Talos.





