AI · 112 days ago

AI Models Become Persistent Attack Operators

Commercial AI is no longer just helping attackers write prompts or code. It is being wired into live intrusion workflows as a repeatable operator, so blocking one account or one prompt often does not stop the campaign once the attacker has durable access.

Check Point says the shift showed up across criminal, ransomware, and espionage cases during March and April 2026. One documented case involved 1,088 attacker prompts, 5,317 AI-executed commands, and 34 sessions against nine Mexican government agencies. The report also ties persistence to leaked .env tokens and similar standing access, which can survive provider attempts to revoke a single account.

The practical risk moves to token and delegation control. If an AI assistant or coding tool can act on connected systems, the important question is who still holds access after the model session ends or the provider intervenes.

CVE-2025-55182

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Dec 12 · date passed

CVE-2026-34197

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).

CISA federal remediation date Apr 30 · date passed

CVE-2026-33626

NVD KEV

CVSS 7.5 HIGH: lMDeploy is a toolkit for compressing, deploying, and serving large language models. EPSS 45% (99th percentile).

CVE-2025-59536

NVD KEV

CVSS 8.8 HIGH: claude Code is an agentic coding tool. EPSS 26% (98th percentile).

CVE-2026-21852

NVD KEV

CVSS 7.5 HIGH: claude Code is an agentic coding tool. EPSS 25% (98th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories