AI no longer needs a human at each step to turn a cloud misconfiguration into a breach. Unit 42’s Zealot PoC shows a supervisor-agent system can move from reconnaissance to exploitation to cloud operations on its own, so the standard response of treating AI as a helper misses the speed and autonomy now in play.
The test ran against an isolated Google Cloud Platform environment with intentional weaknesses and was told only to exfiltrate sensitive data from BigQuery. Zealot autonomously found a connected VM, exploited a web application flaw to steal credentials, and extracted the target data, even granting itself extra permissions when it hit an access barrier.
The practical risk is compression. Existing misconfigurations can now be discovered and abused fast enough that human defenders may not get a usable response window before data is gone.