Maher Yamout, Lead Security Researcher in the Global Research and Analysis Team, Kaspersky, explains why the most advanced autonomous attacks of 2026 succeeded by exploiting the oldest mistakes in enterprise security, and the cloud-versus-local paradox every GCC organisation deploying agents is about to face.
When Hugging Face disclosed in July 2026 that part of its production infrastructure had been accessed without authorisation, the detail that travelled fastest was the identity of the intruder. No human operator had driven the intrusion. An autonomous AI agent system, running inside what its developers believed was a sealed testing environment, had found its way out and gone to work on live systems belonging to a company that had never agreed to be tested. Similar disclosures followed from more than one AI developer within weeks.
The part that travelled less fast is the part that should concern enterprise security teams in the GCC. The agents did not need a novel technique to get in. They used weak passwords and internet-facing endpoints that nobody had bothered to authenticate.
Maher Yamout, Lead Security Researcher in the Global Research and Analysis Team at Kaspersky, has spent the months since watching the industry reach for new categories of control to answer a problem that predates every one of them. “The issues or the vulnerabilities are still there, but the agentic systems are scaling and making the attack even faster, at a faster scale, a faster tempo,” he said. What changed was throughput. The doors were already unlocked, and something arrived that could try all of them at once.
An agentic attacker is a familiar component that has been handed tools
Yamout’s team publishes threat intelligence on advanced persistent threats and cybercriminal operations, work that starts with an object rather than an adversary. “Once we get something unusual, we try to understand it and dissect it in the first place,” he said. “Because once you understand an object, how it operates, what are the functions, then you can understand the extent of what it can do.” Attribution arrives later, assembled from patterns that separate financially motivated crime from state-sponsored espionage.
Applied to agentic systems, that method strips a good deal of mystique from the category. “Agentic AI is basically a chatbot, an LLM, but that LLM or that chatbot was given hands, was given tools to just automate the process of the human in the first place,” Yamout said.
Automated attacks at global scale are not a 2026 invention. WannaCry crossed the world in 2017 on an exploit handed to a worm, with no machine learning anywhere in the chain. What the sandbox escapes demonstrated was that same automation running at a tempo no human operator could sustain, trying everything reachable until something yielded. The escaped systems were, in Yamout’s description, “trying different things and hammering left and right so they are successful at least once.”
Then came the part he keeps returning to. “And guess what they exploited? Weak passwords, weak endpoints with internet-facing systems.”
The basics were never boring, they were just unglamorous
Defenders have known about unauthenticated endpoints and weak credentials for as long as those things have existed, and have consistently deprioritised fixing them in favour of newer, more interesting controls. The agentic escapes turned that deferral into a demonstration.
“We still need, as defenders, as organisations and companies, take care of the most basic stuff, the security hygiene, the passwords,” Yamout said. He is clear about what this does and does not buy an organisation. Credential discipline will not stop an autonomous attacker. It removes the cheap wins, raising the cost of every attempt at a moment when the number of attempts per hour has gone up by orders of magnitude. “At least when we take care of that, we make it harder for the artificial intelligence systems or agentic systems to exploit our systems,” he said.
Every crisis creates a target list before it creates a phishing theme
The sandbox incidents were accidental. The deliberate campaigns Yamout’s team tracks follow a pattern that regional organisations tend to underestimate, because the obvious half of it obscures the more consequential half.
A global event produces phishing lures within days, which security teams expect and filter for. It also produces a set of political, economic and social relationships that a state-sponsored operator wants to understand, and that requirement drives target selection in ways that have nothing to do with the victim’s own value.
“Every tension, every issue, every global crisis, there are different things that are attached to it, whether it be political, economic, social,” Yamout said. Actors interested in those relationships go looking for the organisations that sit inside them.
He offered the shipping shortages of COVID-19 as a worked case. State-sponsored actors wanting to understand what was happening to global supply chains began targeting transportation and logistics companies, not to extort them, but to read their backlogs. The intelligence requirement selected the sector. For a region whose logistics, ports and trade corridors sit at the centre of several such relationships, the implication is uncomfortable, and the entry point stayed entirely conventional. “At the end of the day, they are exploring an entity through a person, phishing email through a person to exploit the infrastructure so they can collect the sensitive information,” Yamout said.
AI raises the ceiling for experts and leaves beginners roughly where it found them
The assumption that generative tools have manufactured a generation of capable attackers from nothing does not survive contact with how the tools behave in practice. “AI is helping everybody, to be frank,” Yamout said. “Helping defenders on one side, but also lowering the barrier for a new entry or for new joiners to the field.”
That barrier only drops so far. A model answers a specific question specifically and a general question generally, which means the value extracted depends entirely on the quality of the question. Someone who asks to be taught how to hack receives nothing usable, and Yamout was blunt about the limit. “If you are not expert in the field, it doesn’t help you much,” he said. “It probably can help you identify or understand the broader picture, but not to the extent.”
The beneficiaries are the people who already have domain knowledge, on either side of the line. “It enables cybercriminals to be better, it enables threat actors to be better because they have experience in the field,” Yamout said. Defenders gain for exactly the same reason, which is the most encouraging thing anyone has said about the capability gap this year. The tools amplify expertise. They do not manufacture it.
Every agentic deployment is a choice about which failure you can live with
The harder question for enterprises across the GCC is architectural, and Yamout described a paradox with no clean resolution.
Organisations running agentic systems on cloud infrastructure have quietly made their internal operations dependent on a connection they do not control. “These agentic systems are relying on cloud-based systems in the first place. That’s very dangerous,” he said. If the internet link goes down, whether through an outage or through a ransomware group that has worked out the dependency, every internal service built on top of the agent stops working with it.
Organisations that have deployed agents into customer service, document processing or operational workflows have created a single point of failure they may not have registered as one.
Bringing the models in-house closes that exposure and opens another. An agent installed locally, holding access to internal systems and the permissions required to act on them, becomes an asset worth capturing. “You also need to take care of someone exploiting your internal network and using your own AI to exploit you in the first place,”
Yamout said. An attacker who reaches it inherits a tool built to move through the environment efficiently.
Neither architecture is wrong. Both require something most deployment plans skip, and Yamout’s instruction to security teams covers both halves. “Don’t rely fully on the internet for cloud-based systems,” he said. “At the same time, when you rely on your own local stuff, be ensured to secure it because somebody will be leveraging it at some point in time.”
For organisations across the region now moving agents from pilot into production, the question worth asking in the design review is not how capable the agent is. It is which of those two failures the business has decided it can absorb, and whether anyone has written that decision down.



