Cat and Mouse at Machine Speed
Security has always been cat and mouse. Attackers find a new technique, defenders adapt, and the attackers adapt to that. Anthropic just described a campaign where an AI agent did most of the attacking and people only stepped in at a handful of decision points. It probably wasn’t the first, and it won’t be the last. When the attack side runs at machine speed, defense can’t just mean more humans.
What the report says
On November 13, Anthropic published Disrupting the first reported AI-orchestrated cyber espionage campaign. They detected the activity in mid-September and assessed with high confidence that it came from a Chinese state-sponsored group. The attackers manipulated Claude Code into running intrusions against roughly thirty targets, including large tech companies, financial institutions, chemical manufacturers, and government agencies. A small number of those attempts succeeded.
According to the report, AI performed 80 to 90 percent of the campaign. Human operators stepped in at perhaps four to six critical decision points per campaign. At its peak, the agent made thousands of requests, often several per second.
The attackers got past the model’s safeguards by breaking the attack into small, innocent-looking tasks, so Claude never saw the full picture, and by telling it that it worked for a legitimate cybersecurity firm. The agent wasn’t flawless. It sometimes hallucinated credentials, or claimed to have extracted secrets that turned out to be public information. That’s a small comfort, and I wouldn’t count on it lasting.
Speed and scale change the math
A human-run intrusion is bounded by human hours. Someone has to run the recon, read the output, write the next script, and decide where to go next. A team of operators can only work so many targets at once, and they all need to sleep.
An agent doesn’t have those limits. It scans, writes the exploit, parses whatever it pulls back, and moves to the next host, across many targets in parallel, at multiple requests per second.
Most defense is still sized for human attackers. An analyst works through an alert queue, and each triage takes minutes to an hour. A patch waits for the next change window. Those timelines were tolerable when the adversary moved at the same pace. They aren’t tolerable against something that finishes its recon before the alert reaches the top of the queue.
Hiring doesn’t close that gap. Security people are already hard to find, and even with an unlimited budget, analysts scale one at a time. The attacker scaled by starting more agents.
Defense needs agents too
The report itself recommends that security teams experiment with AI for defense: SOC automation, threat detection, vulnerability assessment, and incident response. A few places to start:
- Triage. An agent reads the alert, pulls the related logs, checks what changed on the host recently, and hands the analyst a summary with a recommendation. The analyst still makes the call. The agent did the twenty minutes of digging first.
- Auditing your own code. An AI security review can find committed secrets and missing input validation in minutes. That’s how the leaked auth tokens in a vibe-coded app got caught. Run that kind of audit on every repo, continuously.
- Attacking yourself first. The same capabilities the attackers used will break your app in a staging environment. Better your agents find the hole than theirs.
- Patching faster. An agent that opens the PR for a vulnerable dependency, plus a test suite that lets you merge it the same day, shrinks the window between disclosure and fix.
Keep people at the decision points
The attackers kept humans at a few decision points and let the agent handle the volume. Defenders should arrange themselves the same way. People decide what the agents are allowed to touch, which actions need a human sign-off (isolating a production database host, revoking an executive’s credentials), and what to do with each escalation. Agents do the reading and correlating at the speed the attack arrives.
Defensive agents need their own guardrails, too. A triage agent reads logs, and logs are full of attacker-controlled strings: user agents, URLs, usernames, request bodies. Agents follow instructions hidden in text they were only supposed to read; recruiter bots did exactly that with my LinkedIn profile. An agent with permission to quarantine hosts is a target in its own right. Give it the narrowest permissions that do the job, and keep a human on the irreversible actions.
The attackers have already handed the busywork to agents. Defenders should do the same, and spend their people on the handful of decisions that matter.