{"id":9423,"date":"2026-09-10T16:40:56","date_gmt":"2026-09-10T16:40:56","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9423"},"modified":"2026-09-10T16:40:56","modified_gmt":"2026-09-10T16:40:56","slug":"from-jadepuffer-to-multi-agent-intrusions-the-next-wave-of-autonomous-attacks","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9423","title":{"rendered":"From JADEPUFFER to Multi-Agent Intrusions: The Next Wave of Autonomous Attacks"},"content":{"rendered":"<div class=\"elementor elementor-46685\">\n<div class=\"elementor-element elementor-element-39c6e261 e-ecs-flex e-flex e-con-boxed e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-3b69e885 ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Key Takeaways<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1cccb58d elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">JADEPUFFER proved one AI agent could run a full attack chain without a human in the loop.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">ENCFORGE shows the same operator upgrading payloads to destroy AI models and training data specifically.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Unit 42&#8217;s September intrusion adds a new variable: parallelism, not just autonomy.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Multiple specialized agents worked cloud, identity, CI\/CD, and AI infrastructure simultaneously.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">No individual technique was novel; the concurrency of execution was.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Branch protection stopped one persistence attempt, a rare proven preventive control.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Containment now needs to act across every compromised plane at once, not sequentially.<\/span><\/p><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4453aa4 e-ecs-flex e-flex e-con-boxed e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-d6640cf elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Our <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/jadepuffer-and-autonomous-intrusion-operations\/\">first article on this subject looked at JADEPUFFER<\/a>, Sysdig\u2019s July research documenting what it assessed as the first end-to-end ransomware operation run by a single autonomous AI agent, and asked what that meant for enterprise XDR architecture.<\/p>\n<p>Two developments since then show how that model is evolving.<\/p>\n<p>Later in July, Sysdig caught the same operator returning to the same compromised host with ENCFORGE, a ransomware locker purpose-built to destroy AI model weights and training data rather than generic files.<\/p>\n<p>Then, on September 2, Unit 42 disclosed an incident in which a coordinated set of specialized AI agents, working in parallel across a victim\u2019s cloud, identity, CI\/CD, and AI infrastructure, compressed roughly two weeks of intrusion tradecraft into under ten hours. Unit 42 subsequently clarified that the incident was an intrusion, not a ransomware attack, although the attacker did engage in ransom negotiations.<\/p>\n<p>Read together, these two developments extend that original argument in a specific direction. The question then was what changes when an autonomous agent doesn\u2019t need a human between steps.<\/p>\n<p>These follow-on incidents don\u2019t simply show a bigger version of the same problem. They introduce a second variable: parallelism.<\/p>\n<p>One agent removed the human bottleneck from a single attack chain. A coordinated fleet of agents removes it from several attack chains at once.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-903887c elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<p class=\"elementor-heading-title elementor-size-default\">Three takeaways for security leadership<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4a61bb3 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Autonomy and parallelism create different security problems, and the September intrusion provides an early real-world example of the second. JADEPUFFER showed one agent could complete a kill chain unattended. The September intrusion showed multiple specialized agents can run different parts of a kill chain concurrently, across systems a SOC would normally triage as unrelated incidents.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Autonomy and parallelism create different security problems, and the September intrusion provides an early real-world example of the second. JADEPUFFER showed one agent could complete a <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/threat-detection-response\/what-is-a-cyber-kill-chain\/\">kill chain<\/a> unattended. The September intrusion showed multiple specialized agents can run different parts of a kill chain concurrently, across systems a SOC would normally triage as unrelated incidents.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">The September intrusion also shifts attention from detection alone to the speed and coordination of containment. Unit 42&#8217;s own guidance is explicit: isolating one compromised plane while agents remain active in others gives them time to re-establish footholds elsewhere. Containment increasingly needs to happen across planes at once, not one at a time. <\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-228330b0 e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-10a0e150 e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-48a95a8d elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Five Ways You Can Use Deception in the Mythos-like AI Era<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-671407f9 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Generates High-Confidence Alerts<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Disrupts Autonomous and AI-Assisted Attacks<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Extends Detection Across Hybrid Environments<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-6b3138ab elementor-widget elementor-widget-button\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/whitepaper\/using-deception-against-threats-in-the-mythos-like-ai-era\/\"><br \/>\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\"><br \/>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Read the Guide Now<\/span><br \/>\n\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1de86416 e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-22764c0 elementor-widget elementor-widget-image\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-17e12c5 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">What Happened Between JADEPUFFER and Now<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1accc94 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Sysdig disclosed ENCFORGE later in July: the same operator, identified through a matching extortion contact address, returned to the previously compromised Langflow instance and staged a compiled Go ransomware binary purpose-built for AI infrastructure.<\/p>\n<p>Where the original campaign relied on improvised Python scripts and a database\u2019s own encryption function, ENCFORGE targets roughly 180 file extensions across the AI\/ML stack, including model checkpoints, vector databases, training data, and embedding indices.<\/p>\n<p>The operator escalated through an exposed Docker socket to reach root-level host access, then iterated through successive delivery scripts over roughly five minutes to work around failures before the payload landed.<\/p>\n<p>The recovery problem is different from a conventional database attack. Production models, training data, and embedding assets may not have the same backup and recovery coverage as conventional business data.<\/p>\n<p>Sysdig estimates that rebuilding a single affected model can cost $75,000 to $500,000 in compute and engineering time.<\/p>\n<p>The more significant escalation is the one Unit 42 documented independently, in a different environment with a different operator. Unit 42 describes a human attacker who set objectives and then left tactical execution to AI agents that monitored, evaluated, acted, and re-planned in real time.<\/p>\n<p>On September 2, researchers Renzon Cruz, Nicolas Bareil, Eric Semaan, and Omar Jbari published an account of an intrusion that began with a breach of a public-facing API and, ten hours later, had reached across the victim\u2019s cloud, identity, CI\/CD, and AI infrastructure.<\/p>\n<p>Rather than one agent working sequentially, specialized agents worked in parallel: one mapped internal microservices, others combed source repositories for hard-coded tokens and service passwords, another used the harvested credentials to reach the secrets manager and pull root-level administrative credentials, and a pipeline-focused agent triggered unauthorized CI\/CD builds and obtained cloud access keys, which it then used against the victim\u2019s AI infrastructure.<\/p>\n<p>The agents then used those stolen keys to route their own orchestration traffic through the victim\u2019s own AI endpoints, which made it harder to distinguish from ordinary model usage.<\/p>\n<p>One persistence attempt, a backdoor planted in Terraform configuration, failed because branch-protection controls required a second human reviewer before the change could merge.<\/p>\n<p>The attacker told Unit 42 during negotiations that they had used frontier AI models and purpose-built agentic attack frameworks.<\/p>\n<p>Unit 42 found independent technical indicators consistent with that claim: parallel calls to multiple frontier models, structured Markdown files passing state between agent sessions, and the same kind of self-narrating, heavily commented code Sysdig had flagged in JADEPUFFER\u2019s payloads.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-05f0168 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Why This Matters<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-d5c5803 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The original JADEPUFFER analysis made a narrower point: an agent that never sleeps or hesitates can break a detection model built around human pacing. That argument still holds, but the September case extends its scope.<\/p>\n<p>JADEPUFFER was bounded to one agent and one exposed framework. The intrusion Unit 42 documented had no equivalent boundary. Specialized agents worked across cloud, identity, developer tooling, and AI infrastructure at once, the way a coordinated human red team would if a two-week engagement were compressed into a single overnight shift.<\/p>\n<p>For a CISO, an initial reading of this problem might have stopped at: could our controls stop one autonomous agent hitting one exposed service?<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f29dcef ha-has-bg-overlay elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p><em><strong>The harder question now is whether an incident response process can contain an attack that\u2019s already active across several unrelated systems before the first alert has finished triage.<\/strong><\/em><\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-cf9fa87 eael-infobox-icon-bg-shape-none eael-infobox-icon-hover-bg-shape-none elementor-widget elementor-widget-eael-info-box\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-infobox icon-on-left\">\n<div class=\"infobox-icon eael-icon-only\">\n<div class=\"infobox-icon-wrap\">\n                                    <\/div>\n<\/div>\n<div class=\"infobox-content eael-icon-only\">\n<div class=\"infobox-title-section\">\n<div class=\"title\">Reality Check<\/div>\n<\/div>\n<div>\n<p>Neither ENCFORGE nor the September intrusion involved a novel exploitation technique. ENCFORGE reused the original JADEPUFFER entry point against the same target. Unit 42 is explicit that the attacker used no zero-day and no unusually elite tradecraft; every one of the fifty-plus ATT&amp;CK techniques it mapped was already known.<\/p>\n<p>What changed was not sophistication in any single step. It was the removal of a human bottleneck across several steps running concurrently, rather than one.<\/p>\n<\/div><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-34fd482 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Why the Escalation Happened This Fast<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-66c336d e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-0407b9a elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Factor 01: <\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-2b192b6 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">The operator kept iterating<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-33555d4 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>ENCFORGE shows the JADEPUFFER operator treating the original campaign as a first draft: same infrastructure, same entry point, a materially upgraded payload purpose-built for higher-value AI assets.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-a31d3de e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-f15c3ea elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Factor 02:<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-36de530 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Frontier-model access is not a theoretical barrier to offensive use<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1ea8b5c elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The September attacker\u2019s own disclosure, and the technical evidence of parallel frontier-model calls, demonstrates that capable models are already available to whoever is running this kind of operation, not just to organizations building agents for legitimate purposes.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4ceb222 e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-245ac1b elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Factor 03:<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-eb31473 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">AI infrastructure is showing up on both sides of the same equation<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-ac9e3a0 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>JADEPUFFER used an exposed AI framework as its way in. The September attacker used stolen keys to the victim\u2019s own AI infrastructure as a way to hide, once inside.<\/p>\n<p>These are two different incidents and two different mechanisms, but together they show the same broader risk from different directions: AI infrastructure can be an entry point when exposed, and post-compromise infrastructure when an attacker obtains legitimate-looking access to it.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1894795 e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-3ace074 elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Factor 04:<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-ebf9ce3 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Multi-agent coordination moved from research environments into real-world intrusion activity<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4d8a73b elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Specializing separate agents for reconnaissance, credential harvesting, pipeline compromise, and reporting, then running them in parallel, is the same architecture pattern enterprises are adopting for their own agentic workflows. The September intrusion shows attackers beginning to apply that same architecture pattern to offensive operations.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-e875ec6 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">How the Two Incidents Compare<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-a18a571 elementor-widget elementor-widget-Table\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\tDimensionJADEPUFFER (July)Unit 42 intrusion (September)\t\t\t\t<\/p>\n<p>\t\t\t\t\tAgent architectureSingle LLM agentSpecialized agents operating in parallelAttack surfaceOne exposed AI-framework endpointCloud, identity, CI\/CD, and AI infrastructureModel classUnspecifiedFrontier models, attacker-confirmedEstimated human effort compressedNot separately estimatedRoughly two weeks of human red-team work into under ten hoursPersistence attempt blocked byNo equivalent control testedMulti-party branch-protection review on a Terraform changePost-compromise use of AI infrastructureNot applicableStolen keys used to route orchestration traffic through the victim&#8217;s own AI endpointsClassificationRansomware, per Sysdig&#8217;s assessmentIntrusion, per Unit 42&#8217;s own clarified wording\t\t\t\t<\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-23c3e37 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">From Autonomy to Parallelism<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-e6748db elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The original JADEPUFFER analysis centered on autonomy: one agent that can perceive, reason, act, and recover without waiting on a human.<\/p>\n<p>The September case adds a second idea on top of it, parallelism, several agents running that same perceive-reason-act-recover loop across different systems at the same time.<\/p>\n<p>That distinction is worth stating plainly, because it shapes most of what follows. Autonomy compressed the time available to detect and respond to a single attack chain. Parallelism raises a different problem: several attack chains can be running at once, and a defender who catches one may still be blind to the others.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-e621618 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<p class=\"elementor-heading-title elementor-size-default\">Two practical consequences follow.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-2998c40 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Reconnaissance, credential harvesting, secrets-manager compromise, and CI\/CD hijacking can no longer be assumed to occur as sequential stages a defender can catch one at a time; in the September case they ran as parallel workstreams feeding one objective.<\/p>\n<p>And the behavioral signatures worth watching for aren\u2019t quite the same as in a single-agent case. Unit 42 flagged bursty API request patterns, rapid shifts between authentication failure and success, sudden AI-endpoint usage from accounts with no prior history of calling those endpoints, and structured Markdown files passing state between sessions.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-0f6712f elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Identity and the Secrets Layer<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-403e693 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The original analysis also placed identity at the center of nearly every stage of an autonomous intrusion. The September case adds a second path into that same control plane: source code.<\/p>\n<p>Rather than reaching credentials primarily through <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/lateral-movement\/\">lateral movement<\/a> after a foothold, the agents pulled hard-coded tokens and service passwords directly out of repositories, then used those to reach the secrets manager.<\/p>\n<p>Identity compromise and secrets-management compromise are no longer stages a defender can expect in sequence; here they ran as parallel paths to the same objective.<\/p>\n<p>The practical implication is that identity telemetry now needs correlation with source-code and CI\/CD activity, an integration most enterprise detection stacks weren\u2019t built around.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f77993f elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Why XDR&#8217;s Architecture Has to Extend Further<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5771f10 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Those six architectural requirements remain necessary: cross-domain correlation, deep session inspection, technique-level detection, deception, response orchestration, and stack extension rather than replacement. <a href=\"https:\/\/fidelissecurity.com\/fidelis-elevate-extended-detection-and-response-xdr-platform\/\">Fidelis Elevate<\/a>\u00ae, referenced in the original analysis as one working example of those principles, remains a relevant reference point here too. The September case adds requirements the original analysis didn\u2019t anticipate.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-87314db e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-79e8df8 elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Requirement 07<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-0a262e5 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Synchronized, cross-plane containment<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-d08ffde elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Unit 42\u2019s own defensive guidance is explicit: isolating one compromised plane while agents remain active in others gives them time to re-establish footholds elsewhere. Containment now needs to revoke credentials, terminate sessions, freeze pipelines, and isolate cloud accounts across every affected plane at once.<\/p>\n<p>Fidelis Elevate\u00ae\u2018s CommandPost interface, together with its documented SOAR integrations (Splunk, Palo Alto Cortex XDR, D3, Respond), points toward the kind of centralized orchestration this containment requires, though synchronized cross-plane response of this specific kind is an emerging requirement rather than something any platform has been tested against in a documented multi-agent incident.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-61b94de e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-1f66e93 elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Requirement 08<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-07ba965 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">AI infrastructure governed as core security surface<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-87a11ae elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Every model endpoint, API key, and MCP gateway should now be treated as a potential dual-use security asset. JADEPUFFER shows what it looks like as an entry point; the September case shows what it looks like as a covert channel for post-compromise orchestration. Rate limiting, least-privilege policy, and diagnostic logging on AI services are load-bearing controls, not optional hardening.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-eeb879d e-con-full e-ecs-flex e-flex e-con e-child\">\n<div class=\"elementor-element elementor-element-d45e0ce elementor-widget__width-initial ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Requirement 09<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-d1da999 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">DevOps pipeline lockdown as a tested chokepoint<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-6ce7764 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Multi-party review and immutable branch protection on <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/cloud-security\/infrastructure-as-code-iac-security-drives-cloud-confidence\/\">infrastructure-as-code<\/a> repositories stopped the Terraform backdoor attempt in the September incident. It is one of the clearest examples in the incident of a preventive control stopping an agent-driven action rather than simply detecting it.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-79e0a1a elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">CISO Action Checklist<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-064efb4 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Questions to ask your team<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-2d65ecf elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">If an attack is active in our identity plane, our <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/cloud-security\/ci-cd-pipeline-security\/\">CI\/CD pipeline<\/a>, and our cloud environment at the same time, does our incident response process contain all three simultaneously, or one at a time?<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Could our own AI endpoints be used to hide an attacker&#8217;s orchestration traffic inside what looks like normal model usage, and would we notice?<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Do our code repositories contain hard-coded credentials, and how are we detecting them?<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Does any infrastructure-as-code repository lack mandatory multi-party review before merge?<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">If an AI-targeted ransomware attack hits our environment and targets model weights and training data specifically, do we know which of our AI assets would be unrecoverable, and at what cost?<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1a9f13d elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Recommended actions<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-9d7847b elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Extend credential and secrets-scanning coverage to the full repository portfolio, given how fast an agent can enumerate an entire codebase.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Build containment playbooks that trigger synchronized action across cloud, identity, CI\/CD, and AI infrastructure from a single detection, rather than routing each plane through a separate runbook.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Apply production-grade access controls, network isolation, and logging to AI orchestration frameworks rather than treating them as developer tooling.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Monitor for the behavioral signatures Unit 42 identified: bursty API requests, rapid 401\/200 authentication shifts, and AI-endpoint usage from accounts with no history of calling those endpoints.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Extend mandatory multi-party review and immutable branch protection to every infrastructure-as-code repository, not only the ones considered highest-risk today.<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-c6700dd elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Predictions: Where This Goes From Here<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-b6a9663 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/fidelissecurity.com\/use-case\/threat-intelligence\/\">Threat intelligence<\/a> may increasingly track agent architecture, including single-agent versus coordinated multi-agent operations, as a distinguishing characteristic alongside malware and infrastructure.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">The September case suggests that access to frontier models may not be a significant barrier to offensive agentic operations; expect more incidents to test how far that access extends rather than assuming cost alone will limit the next wave.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">AI infrastructure is likely to keep showing up in incident reports on both sides of a compromise, sometimes as the entry vector, sometimes as the channel an attacker uses to stay hidden afterward.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Source-code repositories and secrets managers will be treated as a control plane alongside identity, given how directly the September incident exploited that path.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Multi-party review and immutable infrastructure-as-code controls are likely to receive more attention after demonstrating their value as a concrete chokepoint in this incident.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Synchronized, cross-plane containment capability is likely to become a named evaluation criterion in <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/xdr-security\/xdr-vs-siem-vs-soar\/\">XDR and SOAR<\/a> procurement, distinct from single-domain detection capability.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Other threat actors are likely to experiment with ransomware payloads purpose-built for AI\/ML assets, following the pattern ENCFORGE established.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Expect threat reporting to draw sharper distinctions between autonomous intrusion, autonomous ransomware, and AI-assisted attacks as more real-world cases emerge.<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-46211cf elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-dd1fd08 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The original JADEPUFFER analysis argued that autonomous execution changes the tempo of an attack chain. These two developments extend that argument along a second axis: parallel execution changes its scale.<\/p>\n<p>JADEPUFFER demonstrated that one agent could complete a kill chain without a human between steps. The September intrusion demonstrated that several specialized agents can run different parts of a kill chain at the same time, across systems a SOC would ordinarily treat as separate incidents.<\/p>\n<p>Nothing about the individual techniques in either case is new, and that\u2019s the point both pieces make: the defensible unit was never the isolated exploit.<\/p>\n<p>It\u2019s the correlated attack chain, now running across more planes at once and increasingly making use of the organization\u2019s own AI infrastructure while it works.<\/p>\n<p>Organizations that treat synchronized cross-plane containment and AI infrastructure governance as baseline architecture will be better positioned to interrupt this class of attack before it becomes business-impacting.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f4b4752 ha-has-bg-overlay elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p><em><strong>The implication for defenders is straightforward: preparing only for faster attack chains is no longer enough when multiple chains can execute in parallel.<\/strong><\/em><\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-750c48e content-align-cta-default elementor-widget elementor-widget-eael-cta-box\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-call-to-action cta-basic bg-img cta-preset-1\">\n<p class=\"title eael-cta-heading\"><span class=\"eael-cta-title-text elementor-repeater-item-4182408\">Our customers detect<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-49f9954\">post-breach attacks over<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-bb4e738\">9x Faster<\/span> <\/p>\n<p>Detect Advanced Threats Before Damage Escalates TrustedCybersecurity Leader for 20+ YearsSee why security teams choose us over other solutions<a href=\"https:\/\/fidelissecurity.com\/get-a-demo\/\" class=\"cta-button cta-preset-1  \">Request a Demo<\/a><a href=\"https:\/\/fidelissecurity.com\/resource\/demo\/fidelis-elevate-in-action\/\" class=\"cta-button cta-secondary-button \">See Fidelis in Action<\/a>\t<\/p><\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5a6cb75 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<p class=\"elementor-heading-title elementor-size-default\">Sources:<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f24db47 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/fidelissecurity.com\/#cite1\">^<\/a><a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models\" target=\"_blank\" rel=\"noopener\">https:\/\/www.sysdig.com\/blog\/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite2\">^<\/a><a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion\" target=\"_blank\" rel=\"noopener\">https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite3\">^<\/a><a href=\"https:\/\/unit42.paloaltonetworks.com\/ai-assisted-cyber-attack-inside-a-unit-42-investigation\/\" target=\"_blank\" rel=\"noopener\">https:\/\/unit42.paloaltonetworks.com\/ai-assisted-cyber-attack-inside-a-unit-42-investigation\/<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite4\">^<\/a><a href=\"https:\/\/attack.mitre.org\/\" target=\"_blank\" rel=\"noopener\">https:\/\/attack.mitre.org\/<\/a>\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/from-jadepuffer-to-multi-agent-intrusions-the-next-wave\/\">From JADEPUFFER to Multi-Agent Intrusions: The Next Wave of Autonomous Attacks<\/a> appeared first on <a href=\"https:\/\/fidelissecurity.com\/\">Fidelis Security<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Key Takeaways JADEPUFFER proved one AI agent could run a full attack chain without a human in the loop. ENCFORGE shows the same operator upgrading payloads to destroy AI models and training data specifically. Unit 42&#8217;s September intrusion adds a new variable: parallelism, not just autonomy. Multiple specialized agents worked cloud, identity, CI\/CD, and AI [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9424,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-9423","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9423"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9423"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9423\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9424"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}