Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Can an Autonomous AI Agent Increase Your Company's Cyberattack Risk?

Lead

An autonomous AI agent does not need to bypass sophisticated security controls to create a material business risk. It may only need to find an internet-exposed service, an outdated configuration, an administrative panel, or an accidentally exposed token — while performing reconnaissance faster and at a greater scale than a single human operator.

For business leaders, the key question is no longer “will someone use AI to attack us?” It is: “What parts of our infrastructure are visible from the internet, and can we justify that exposure?” An Internet Exposure Scan helps answer that question without interfering with the client's systems.

What Did the Autonomous AI Attack Show?

Unit 42 described a campaign in which a threat actor combined the DeepSeek model with the Hermes Agent framework and Telegram-based control. The agent independently searched for internet-facing systems, assessed vulnerabilities, sourced publicly available tools, and initiated exploitation attempts.

This represents an operational change. The issue is not only that an AI model can generate code. An agent can connect several steps into one workflow: infrastructure discovery, target selection, configuration assessment, tool preparation, and repeated execution attempts.

The reported campaign included both autonomous reconnaissance and manual activity by the operator. It does not mean that every AI agent is an autonomous attacker, but it demonstrates that the barrier to automating offensive workflows continues to decline.

Why Is Internet Exposure the Starting Point?

An autonomous agent can act only on information, systems, and access that it can discover or obtain. That is why an organisation's public exposure — domains, subdomains, DNS records, services, ports, login panels, and technology metadata — remains a core risk-control area.

Systems used for business-process automation, API integrations, marketing operations, and data handling deserve particular attention. An exposed workflow panel, an unnecessary open port, or a service without adequate authentication can become a starting point for further environment analysis.

What Can Be Visible Externally?

  • domains, subdomains, and DNS records, including forgotten test environments,
  • internet-facing services, open ports, and technology banners,
  • administrative panels, workflow systems, webhooks, and API endpoints,
  • TLS configuration and website security headers,
  • SPF, DKIM, and DMARC records that help prevent domain impersonation,
  • metadata that reveals technologies, software versions, or environments.

Where Do AI-Adopting Companies Make Mistakes?

The language model itself is not usually the core problem. Risk emerges at the intersection of autonomy, broad privileges, tool access, and infrastructure misconfiguration.

An agent connected to a VPS, email account, CRM, API, code repository, or automation system can perform valuable operational work. It also requires guardrails: least-privilege access, environment separation, secrets management, activity monitoring, and deliberately defined network access.

Five Controls Worth Implementing

  1. Do not expose administrative panels unnecessarily. Workflow tools, dashboards, VPS panels, and automation systems should be protected with strong authentication, VPN access, IP allowlisting, or SSO.
  2. Keep secrets outside HTTP-served directories. API keys, .env files, access tokens, and SSH keys should not be stored in directories served by a web or file server, or in public code repositories.
  3. Give agents only the permissions they need. Use dedicated service accounts, scope-limited tokens, and separate production, testing, and experimental environments.
  4. Maintain a current exposure inventory. Your company should know which domains, subdomains, services, and integrations are visible from the internet — and who owns them.
  5. Treat exposure changes as security events. A new subdomain, open port, DNS modification, or publicly accessible panel may support a business need, but it should also trigger a security review.

What Does an Internet Exposure Scan Check?

An Internet Exposure Scan is a low-impact review of information and services publicly visible from the internet. It is not a penetration test and does not involve attempts to break into client systems.

CHORS.NET reviews areas including domains and DNS, corporate email configuration, TLS, basic security headers, and visible ports and services. Findings are delivered in a prioritised report designed to be useful to business owners, executives, and technical teams.

The review helps establish what an attacker or autonomous agent can observe before taking further action. It is a practical first step before a deeper, authorised technical assessment when findings require validation.

CHORS.NET Expert View

“AI agents increase the speed of work on both sides: companies use them to automate sales, service, and analysis, while attackers can reduce reconnaissance and target-selection time. The foundation remains unchanged: an organisation must know what it exposes to the internet, who owns it, and which elements need immediate correction.” — Eng. Marcin Białczyk, Founder and Cybersecurity Operator at CHORS.NET.

Author profile: Marcin Białczyk — CHORS.NET

Marcin Białczyk combines business-operations architecture with practical cybersecurity work for B2B organisations. At CHORS.NET, he focuses on exposure identification, risk classification, and translating technical findings into operational priorities.

Frequently asked questions

Can an AI agent perform a cyberattack on its own?

An AI agent can automate parts of an attack chain, including identifying internet-facing systems, analysing technical information, selecting tools, and executing tasks within an environment it can access. A successful compromise still depends on target vulnerabilities, configuration, security controls, and operator supervision.

Does using AI and automation make a company unsafe?

No. AI and automation can improve productivity, service quality, and process speed. Risk increases when agents receive excessive permissions, connect to uncontrolled integrations, or run on poorly secured infrastructure.

How is an Internet Exposure Scan different from a penetration test?

An Internet Exposure Scan analyses publicly available signals and an organisation's externally visible footprint without interfering with its systems. A penetration test or vulnerability assessment is a deeper, authorised activity performed within an agreed scope and with the client's written permission.

How often should we run an Internet Exposure Scan?

Run one before launching a new domain, application, API integration, AI tool, or VPS environment. Regular reviews are particularly useful after infrastructure changes, system migrations, automation deployments, or a security incident.

CTA

You do not need to assume that your company will become the target of an autonomous attack to reduce risk. Start by establishing what is visible from the internet and which elements require priority remediation. Request an Internet Exposure Scan from CHORS.NET.

Sources

  1. Unit 42 — Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
  2. The Cyber Signal — Unit 42 Names the Toolchain: DeepSeek Run Through Hermes Agent
  3. CHORS.NET — Internet Exposure Scan
  4. CHORS.NET — Vulnerability Audit
  5. Marcin Białczyk — author profile, CHORS.NET

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.