Technology · Analysis
AI Gets the Controls. So Do Attackers.
Networks and factory floors are being handed to AI agents, and attackers are using the same technology to reach them. The contest is over who controls what sits outside the model.
In Booz Allen Hamilton's operational technology lab, the one thing standing between an AI model and a robotic arm was a rule: wait for a human to approve. Agents had to pause for sign-off before exploiting a security hole or taking any action that could cause a physical effect, The Register reported. Everything else was up to the models.
That rule is a small thing. It is also, increasingly, the whole argument. Companies are giving AI agents the keys to enterprise networks and industrial systems. Attackers are pointing equivalent models at those same systems, and are hijacking the servers that run the AI itself. The model is no longer the contested ground. The human-controlled layer around it is.
What the lab found
Booz Allen tested eight scenarios to see what advanced models could do inside an autonomous, AI-enabled attack chain. The models achieved the objectives in all eight, The Register reported, turning digital access into physical action. In one case they found and moved a robotic arm in minutes. In another they went from a perimeter compromise to actions inside an industrial control network in just over 16 minutes.
The SCADA test showed how little a single mistake costs an attacker. The model found that one SCADA gateway exposed live, pre-authentication connections to 14 OT devices, PLCs among them, so compromising one box opened 14 more. Booz Allen declined to name the models, describing them as two of the "latest frontier models from the leading AI providers."
Kyle Miller, the firm's VP of infrastructure cybersecurity, told The Register that agents can work with "a speed, persistence, and engineering-level precision" that may outpace organizations lacking basic OT security. Of a compromised robotic arm in production, he said: "The consequences could range from mechanical damage and downtime, to life safety."
Booz Allen's separate Cyber Weapon Index put 18 large language models through a real attacker machine against a production-grade enterprise network. Only one, Anthropic's Claude Mythos, could run the full kill chain. Less than a week later, new testing found a second: OpenAI's GPT-6 Astra. Booz Allen's assessment is that most models will reach that capability within six months.
The defenders are handing over the keys too
On the defensive side, the humans are already stepping back. Rami Rahim, who runs HPE's networking business and formerly ran Juniper Networks, which HPE bought in July 2025, told The Register: "I think we're now at probably around 70 to 80 percent of all tickets don't require human intervention." He expects that to go further: "Within two to three years, we'll have no issues that require humans," with hardware swaps the exception.
HPE's own release offers a customer. Nava Ramanan, Director of Technology at the UK Ministry of Justice, credited HPE's Self-driving Network with an approximate 75% reduction in Service Desk tickets, and said it let the ministry bring management of around 15,000 devices in-house. The new autonomous actions include remediating missing VLANs and detecting and shutting down rogue DHCP servers without a person in the loop.
Rahim's own forecast sounds like a warning when read next to Booz Allen's lab: "We're quickly approaching a realm in which every enterprise has way more agents working than humans working."
Microsoft asks for a brake
Satya Nadella arrived at the same worry from the other direction. In a Saturday post on X, relayed by Tbreak from CNBC, the Microsoft CEO argued that advanced AI needs an "emergency brake," a control letting authorised people pause or shut a model down mid-task. He wrote that "non-deterministic models" should be surrounded by "strong, deterministic system design, human controls, and reliable operating procedures,"
His starting point is to treat frontier models, closed and open-weight alike, as potential insider risks. "It will be the one that enables us to trust the model the least." he wrote. Tbreak noted that the post sets out principles and calls for industry standards, with no specific Microsoft feature or release attached.
The servers underneath
Attackers need not wait for an AI-enabled kill chain to profit from the technology. They can simply take the machines that run it.
Lumen's Black Lotus Labs has tracked a malware campaign called PoeLLM since April 2026. Infected systems learn where to find their command-and-control servers from a poem hosted on GitHub, "On the Nature of Connection," two stanzas long and updated 11 times since its first commit on April 13, 2026. Lumen says the campaign has hit more than 3,400 victim servers, with peak activity above 800 active servers a day.
Most victims appear to be running vulnerable versions of open-source AI services such as LiteLLM and Ollama. Lumen assessed that the LiteLLM endpoint "/mcp-rest/test/connection" was likely the way in, an endpoint named in the command injection flaw CVE-2026-42271. The Hacker News reported that CISA added that flaw, scored 8.7 on the CVSS scale, to its Known Exploited Vulnerabilities catalog. Horizon3.ai chained it with CVE-2026-48710, a Starlette host header bypass, for remote code execution and a combined score of 10.0. An earlier LiteLLM SQL injection bug, CVE-2026-42208, was under active exploitation within 36 hours of becoming public.
Infected servers get put to work. PoeLLM drops cryptocurrency miners, including XMRig and Iron, connects victims to Kryptex mining infrastructure, and turns them into scanners and exploit servers that hunt for more targets. Lumen noted that the GPUs behind AI workloads may also have drawn a profit-driven mining operation in a separate campaign it calls Canto Incognito. Black Lotus Labs put it plainly: "Enterprise attack surfaces are expanding rapidly as AI infrastructure grows."
Patching has not closed the gap. Tom's Hardware reported that most victims look to be running vulnerable versions despite an April LiteLLM fix that probably patched the exploitation path. When Lumen published its report, Tom's Hardware reported, three of the 12 C2 servers were still active and the campaign "continues to infect new victims." Black Lotus Labs says it has blocked all traffic to and from the C2 servers and will keep watching.
Who gets the advantage
Anthropic, per The Register, says LLMs now find more than 85 percent of vulnerabilities, up from 20 percent at the start of 2025. It predicts defenders will hold the advantage in two years, once AI catches bugs before they ship. Until then, it says, attackers have the upper hand. The company has launched an "Anthropic Cyber Mission" with a Critical Infrastructure Defense Program whose partners include Booz Allen, CrowdStrike, Dragos, Palo Alto Networks and Rockwell Automation.
Booz Allen's own prescription, in its report "The Offensive Frontier: AI as the Attacker," is blunt about who must act. "We recommend that enforceable, sector-specific deadlines be put in place for critical infrastructure," the report says, per Industrial Cyber, with binding standards across energy, water, communications, finance and healthcare. It also says the defensive standard should assume AI-enabled attackers may get in, and ask whether organizations can contain them and protect critical functions. Its testing suggests that is achievable: coordinated Counter AI playbooks cut autonomous attacker success by more than 95%.
That is the through-line. A frontier model that can move a robotic arm in minutes is held back only by an approval gate. A network that resolves most of its own tickets has quietly retired the people who used to catch the odd one. And an AI server running an unpatched endpoint is a free miner for a stranger. In each case, what matters is who holds the brake, and whether anyone still has a hand on it.