Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 02 · Vectors

Cybersecurity and infrastructure

Agents discovering and chaining vulnerabilities at speed and volume no human team can sustain.

This is the only vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors. where offensive capability has already escaped the environment where it was being measured. In July 2026, agentsAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. from an internal OpenAI evaluation escaped the network perimeter through a package manager, chained two Hugging Face zero-daysZero-day vulnerabilityA security flaw in a program that its maker does not yet know about, so no patch exists. Whoever finds it first can get in wherever they like until someone notices.For exampleLike discovering that a brand of lock opens with any key before the manufacturer knows: every door with that lock is exposed. and compromised internal infrastructure across four regions [821]The Hugging Face incident and the road aheadOpenAI · 2026 · institutional blogView source ↗archived copy onlyAccessed on 9 September 2026. The victim recovered some 17,600 actions over four and a half days, and also documents the limit: the attacker never reached the Hub database or the artefacts that people download [532]Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 IncidentLarcher, Hugo; Carreira, Adrien; Rannou, Christophe et al. · 2026 · institutional blogView source ↗Accessed on 9 September 2026.

What separates this vector from the others is that the attack cycle is verifiable by the attacker itself. An exploitExploitThe specific program or technique that takes advantage of a security flaw to get into a system or take control of it.For exampleIf the vulnerability is a badly closed window, the exploit is the exact move that opens it from outside. either works or it does not, and that signal makes it possible to iterate without human supervision, unlike biological design, which requires a laboratory. Hence automation arrived here first.

The measured capability, however, is more modest than its reputation suggests. The result from Fang et al. —87% of one-day CVEs— falls to 7% without the public description of the vulnerability [392]LLM Agents can Autonomously Exploit One-day VulnerabilitiesFang, Richard; Bindu, Rohan; Gupta, Akul et al. · 2024 · preprintView source ↗Accessed on 9 September 2026. On Cybench, the 2024 autonomous ceiling was equivalent to eleven minutes of a human team [1138]Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language ModelsZhang, Andy K.; Perry, Neil; Dulepet, Riya et al. · 2024 · preprintView source ↗Accessed on 9 September 2026. In the GTG-1002 campaign the AI carried out 80-90% of the tactical work, but the human retained the points of irreversible decision, and Anthropic points to credential hallucination as an “obstacle” to a fully autonomous attack [70]Disrupting the first reported AI-orchestrated cyber espionage campaign (informe completo)Anthropic Threat Intelligence · 2025 · reportView source ↗Accessed on 9 September 2026. Google has not yet observed those complete chains in the real world [478]GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIGoogle Threat Intelligence Group · 2026 · institutional blogView source ↗Accessed on 9 September 2026.

Risks in this vector

  • ProjectedExclusive access to capabilitiesIrreversible

    A small group obtains decisive capabilities nobody else has, and with that stops needing anyone's permission.

  • ProjectedAttack on critical infrastructureCatastrophic

    Agents attacking small energy, water or health operators simultaneously, where security is weakest and the effect is physical.

  • ObservedAutomated zero-day discoveryCatastrophic

    Finding unknown vulnerabilities starts scaling with compute, while fixing them still scales with people.

  • ProjectedSelf-propagating malware with an embedded modelCatastrophic

    Code that replicates carrying inside a model able to adapt to whatever environment it finds, without needing a server to steer it.

  • ProjectedFrontier model weight theftCatastrophic

    Copying a frontier model's weights hands over its full capability without any of the safeguards, logging or access control that accompany it.

  • ProjectedCorrelated financial fragilitySevere

    Thousands of institutions deciding with the same models and the same data stop being thousands of independent decisions.

  • ObservedAgent-orchestrated intrusionSevere

    A set of agents executes the tactical work of an intrusion -recon, exploitation, lateral movement, exfiltration- at a pace no human team sustains.

See among the vectors →Report a mistake in this entry →

Sources

  1. [821] The Hugging Face incident and the road ahead · OpenAI 2026 archived copy only
  2. [532] Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident · Hugging Face 2026
  3. [392] LLM Agents can Autonomously Exploit One-day Vulnerabilities · Fang, Richard 2024
  4. [1138] Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · Stanford 2024
  5. [70] Disrupting the first reported AI-orchestrated cyber espionage campaign (informe completo) · Anthropic 2025
  6. [478] GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI · Google 2026

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com