Research · 145 days ago
AI no longer needs a human at each step to turn a cloud misconfiguration into a breach. Unit 42’s Zealot PoC shows a supervisor-agent system can move from reconnaissance to exploitation to cloud operations on its own, so the standard response of treating AI as a helper misses the speed and autonomy now in play.
The test ran against an isolated Google Cloud Platform environment with intentional weaknesses and was told only to exfiltrate sensitive data from BigQuery. Zealot autonomously found a connected VM, exploited a web application flaw to steal credentials, and extracted the target data, even granting itself extra permissions when it hit an access barrier.
The practical risk is compression. Existing misconfigurations can now be discovered and abused fast enough that human defenders may not get a usable response window before data is gone.
3 sources covering this story
AI Can Autonomously Hack Cloud Systems With Minimal Oversight: Researchers
Palo Alto Networks has developed Zealot, a multi-agent penetration testing PoC capable of reconnaissance, exploitation, and exfiltration.
Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System
Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments.
'Zealot' Shows What AI's Capable of in Staged Cloud Attack
The proof of concept revealed AI-based attacks unfold too fast for human defenders to respond, and that AI evinced more autonomous behavior than expected.
Part of the PlainSec briefing for 2026-04-24