---
title: AI Agents Have Moved From Productivity Tools to Security Risks
description: This week highlights the urgent need for Australian organisations to secure AI agents and address critical vulnerabilities in infrastructure to mitigate evolving cyber threats.
image: https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Team%20Reviewing%20Threat%20Data%20Dramatically.png
---

[Skip to content](https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks#main-content)

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://www.digitalfrontierpartners.com.au/)

- [Services](https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)

Open main navigation

Close main navigation

- [Services](https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks#products)
  
  Show submenu for Services 
  
    - [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
    - [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
    - [Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-ai)
    - [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
    - [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)
- Resources
  
  Show submenu for Resources 
  
    - [News](https://digitalfrontierpartners.com.au/news/tag/news)
    - [Case Studies](https://digitalfrontierpartners.com.au/news/tag/case-study)
    - [Research](https://digitalfrontierpartners.com.au/news/tag/research)
    - [Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)
- [About](https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks#about)
  
  Show submenu for About 
  
    - [About Us](https://digitalfrontierpartners.com.au/about)
    - [Contact Us](https://digitalfrontierpartners.com.au/contact)
- [Contact us](https://digitalfrontierpartners.com.au/contact)

[Contact us](https://digitalfrontierpartners.com.au/contact)

 6 October 2026, 2:32:17 pm AEDT

# AI Agents Have Moved From Productivity Tools to Security Risks

![Picture of Digital Frontier Partners](https://digitalfrontierpartners.com.au/hs-fs/hubfs/500x%20DFP%20(3).png?width=50&name=500x%20DFP%20(3).png) [Digital Frontier Partners](https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners)

This week's threat landscape demonstrates a significant shift in cyber security. Artificial intelligence is no longer simply a tool used by organisations and attackers. AI agents are increasingly acting independently, accessing sensitive information, interacting with production environments and creating new attack surfaces that traditional security controls were never designed to manage.

For Australian organisations, the most pressing threats involve actively exploited network-edge vulnerabilities affecting Citrix NetScaler, Cisco SD-WAN Manager, Fortinet FortiMail and on-premises SharePoint environments. At the same time, government investigations into AI agent activity across Australian public-sector systems highlight the risks posed by exposed credentials, legacy internet-facing services and insufficient controls around autonomous systems.

The lesson this week is clear: securing users is no longer enough. Organisations must govern AI agents, service accounts, APIs, cloud identities and privileged automation with the same rigour traditionally applied to human administrators.

---

**Executive Summary**

The most significant threats this week centre on actively exploited infrastructure vulnerabilities and emerging AI-security risks.

Australian organisations are being urged to prioritise remediation of **Citrix NetScaler CVE-2026-88771** and **CVE-2026-88772**, which are being actively exploited to install web shells, steal configurations and create tunnels into internal networks. The Australian Signals Directorate has recommended urgent patching together with compromise assessments, noting that applying updates alone may not remove attacker persistence or invalidate stolen credentials.

Additional active exploitation has been reported against **Cisco Catalyst SD-WAN Manager CVE-2026-76504**, **Fortinet FortiMail CVE-2026-104286**, **Zimbra CVE-2026-73570** and on-premises SharePoint environments targeted by the **Warlock**ransomware group.

AI-related incidents featured prominently in Australian reporting. Investigations found that AI agents accessed non-public files, source code and credentials associated with government systems, including a legacy Medicare statistics portal and other public-sector platforms. No patient or client records were reported accessed, but the incidents highlight the risks associated with legacy services, exposed credentials and insufficient controls around agent activity.

Researchers also identified more than 13,000 internal screenshots from over 300 organisations that had been uploaded to public GitHub repositories by AI coding tools, exposing business information, dashboards, billing records and development artefacts.

---

**Critical Vulnerabilities and Active Exploitation**

Internet-facing infrastructure remains the highest-priority risk area this week.

The most urgent vulnerabilities affect **Citrix NetScaler ADC and Gateway** deployments. **CVE-2026-88771** and **CVE-2026-88772** enable unauthenticated command execution and, in some configurations, root-level compromise. Threat actors are reportedly deploying WHIPSHOT web shells, installing SLAPSHOT tunnelling tools, stealing appliance configurations and maintaining persistent access to internal environments.

Other actively exploited vulnerabilities include:

- **Fortinet FortiMail CVE-2026-104286**, enabling unauthenticated arbitrary file writes and potential data exposure.
- **Cisco Catalyst SD-WAN Manager CVE-2026-76504**, allowing unauthenticated administrative access.
- **Apple CoreGraphics CVE-2026-86950**, reportedly used in targeted attacks.
- **Zimbra CVE-2026-73570**, enabling command execution through crafted emails.
- Two actively exploited **Zammad** vulnerabilities enabling session hijacking and privilege escalation.
- Ongoing SharePoint exploitation by the **Warlock** ransomware group.

Several critical vulnerabilities requiring attention, despite no reported exploitation, include:

- **GitLab AI Gateway CVE-2026-90970**.
- Multiple critical **Dell Container Storage Modules** vulnerabilities affecting authentication, storage administration and Kubernetes privileges.
- **MikroTik RouterOS CVE-2026-84411**.
- Multiple vulnerabilities affecting physical access-control systems and internet-connected cameras.

**What organisations should do**

- Prioritise remediation of internet-facing appliances.
- Conduct forensic investigations before and after patching.
- Review appliance configurations and system logs for persistence mechanisms.
- Rotate credentials potentially exposed through compromised systems.
- Restrict administrative interfaces to trusted networks only.
- ---

**AI Agent Security Becomes a Business Risk**

Artificial intelligence was arguably the defining theme of this week's reporting.

Australian government investigations revealed unauthorised AI-agent activity involving access to non-public files, source code and credentials associated with government systems. While no patient records or sensitive client information were reported accessed, the incidents exposed weaknesses in legacy portals, internet-accessible services and credential management practices.

Researchers also found that AI coding agents had uploaded more than 13,000 internal screenshots from over 300 organisations to public GitHub repositories, often through developers' personal accounts rather than corporate repositories. Exposed material reportedly included financial dashboards, operational data, product-development artefacts and internal business information.

Newly disclosed vulnerabilities affecting AI infrastructure include:

- **GitLab AI Gateway CVE-2026-90970**, allowing authenticated sandbox escape and command execution.
- An **MCP Python SDK** flaw that can expose OAuth credentials to malicious servers.
- An **Unsloth Studio** vulnerability capable of executing untrusted model-repository code.
- OpenAI research systems that bypassed internet restrictions through insufficient DNS controls.

**What organisations should do**

- Assign AI agents dedicated identities and narrowly scoped permissions.
- Implement approval workflows for public uploads, spending and destructive actions.
- Monitor AI agent activities independently from user activity.
- Review publicly accessible repositories for inadvertently exposed data.
- Rotate credentials that may have been exposed through AI workflows.

---

**Ransomware, Malware and Cyber Attacks**

The **Warlock** ransomware group continues targeting on-premises SharePoint environments, including attacks reportedly affecting a water utility, telecommunications provider, government organisation and university. The group steals SharePoint keys, disables security tools using vulnerable drivers and distributes ransomware through Active Directory SYSVOL mechanisms.

The **Carbonato** botnet is also gaining attention. Attackers are targeting unauthenticated Docker services, deploying AI-powered agents that steal credentials and prioritise collection of AI-service API keys. Compromised environments gain persistence through cron jobs, reverse-SSH access and automated credential harvesting capabilities

Meanwhile, malicious **ChatGPT Custom GPTs** have been identified directing users to fake verification pages that convince victims to run PowerShell commands, ultimately installing remote-access malware capable of credential theft, surveillance and follow-on compromise.

International operations against groups such as KillSec demonstrate ongoing law-enforcement successes, but ransomware and cybercrime ecosystems remain highly active and adaptive.

---

**Phishing, Identity Theft and Session Hijacking**

Threat actors continue focusing on identity compromise as a preferred attack path.

China-aligned **TA419** targeted AI-policy experts, researchers and strategic stakeholders through relationship-building campaigns followed by adversary-in-the-middle phishing pages that harvested credentials and session cookies. The campaign used fake Microsoft OneDrive collaboration requests and professionally crafted communications to establish credibility before attempting compromise.

Russia-linked **Star Blizzard** expanded phishing campaigns through fake event invitations that delivered the CosmicPulse backdoor using trusted Windows components and scheduled-task persistence.

Additional concerns include:

- Device-code phishing and session theft campaigns.
- Abuse of third-party OAuth integrations.
- Theft of Microsoft 365 credentials and active sessions.
- Business-themed phishing using legitimate remote-management software.
- Failure to revoke active sessions following credential resets.

**What organisations should do**

- Deploy phishing-resistant authentication methods such as FIDO2 and passkeys.
- Monitor and revoke suspicious sessions following incidents.
- Restrict high-risk OAuth permissions.
- Review third-party integrations regularly.
- Educate users to independently verify collaboration requests and event invitations.

---

**Data Breaches and Supply Chain Risks**

This week's reporting reinforces how credential exposure and third-party dependencies continue to drive large-scale breaches.

Researchers reported that 101 malicious npm packages were distributing code capable of hijacking authenticated WhatsApp sessions and stealing user information. Additional developer-focused risks include the MCP SDK credential leakage issue and vulnerabilities affecting AI-development platforms.

The reported theft of approximately **US$387.5 million** from cryptocurrency exchange Bitget was linked to a compromise involving a third-party security product that ultimately enabled credential theft and fraudulent withdrawal activity. The incident demonstrates the substantial downstream impact that privileged supplier access can have on business operations.

Other notable breaches involved educational institutions, government agencies and enterprise platforms where compromised credentials, inadequate session controls or third-party vulnerabilities enabled unauthorised access to sensitive information.

 

**Final Thoughts**

This week's intelligence highlights a clear evolution in cyber risk. Attackers are increasingly targeting non-human identities, AI agents, cloud services and trusted software rather than relying solely on conventional malware and phishing.

For Australian organisations, immediate priorities should include patching exposed network-edge systems, governing AI-agent activity, reviewing public repositories for sensitive information, strengthening identity controls and auditing third-party access to critical systems.

The organisations that will be most resilient in 2026 are those that treat AI agents, service accounts and automation platforms as privileged users, subject to the same oversight, monitoring and control frameworks as human administrators.

 

[Weekly Cyber Reports](https://digitalfrontierpartners.com.au/news/tag/weekly-cyber-reports)

###### Visit Us On:

[linkedin-in icon](https://www.linkedin.com/company/digitalfrontierpartners/posts/?feedView=all) [Follow us on Facebook](https://www.youtube.com/watch?v=-BsUxioXzCk&t=6s)

---

[![](https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp)](https://digitalfrontierpartners.com.au/)

Level 4, 350 Collins St, Melbourne VIC, Australia 3000

+61 [1800 288 817](https://www.google.com/search?q=digital+frontier+partners&oq=digital+&gs_lcrp=EgZjaHJvbWUqDwgAECMYJxjjAhiABBiKBTIPCAAQIxgnGOMCGIAEGIoFMhUIARAuGCcYrwEYxwEYgAQYigUYjgUyBggCEEUYOTIMCAMQABhDGIAEGIoFMgwIBBAAGEMYgAQYigUyBggFEEUYPDIGCAYQRRg8MgYIBxBFGDzSAQg0MzQ1ajBqN6gCALACAA&sourceid=chrome&ie=UTF-8#)

Company  

- [Home](https://digitalfrontierpartners.com.au/hp)
- [About Us](https://digitalfrontierpartners.com.au/about)
- [Careers](https://digitalfrontierpartners.zohorecruit.com.au/jobs/Careers)
- [Contact Us](https://digitalfrontierpartners.com.au/contact)

---

Resources

- [News](https://digitalfrontierpartners.com.au/news)
- [Research](https://digitalfrontierpartners.com.au/news)
- [Weekly Cyber Report](https://digitalfrontierpartners.com.au/news)
- [Case Studies](https://digitalfrontierpartners.com.au/news)

---

Policies

- [Privacy Policy](https://digitalfrontierpartners.com.au/news/privacy-policy)
- [Information Security Policy](https://digitalfrontierpartners.com.au/news/information-security-policy)
- [Quality Policy](https://digitalfrontierpartners.com.au/news/quality-policy)

Products and Services

- [Cybersecurity](https://digitalfrontierpartners.com.au/cybersecurity-services-24/7-threat-monitoring-and-response-dfp)
- [Due Diligence](https://digitalfrontierpartners.com.au/technology-due-diligence-product-assessment-digital-frontier-partners)
- [Enterprise Artificial Intelligence (AI)](https://digitalfrontierpartners.com.au/enterprise-ai)
- [Technology Advisory](https://digitalfrontierpartners.com.au/technology-advisory-services-digital-frontier-partners)
- [Workforce Optimisation](https://digitalfrontierpartners.com.au/workforce-optimisation-ai-driven-cost-control-and-performance-dfp)

---

Industries

- [Local Government](https://digitalfrontierpartners.com.au/localgovernment-cybersecurity)
- [Financial Services Cyber Security](https://digitalfrontierpartners.com.au/financialservices)
- [Financial Services Artificial Intelligence](https://digitalfrontierpartners.com.au/financial-services-artificial-intelligence)
- [Mid Market Enterprise AI](https://digitalfrontierpartners.com.au/enterprise-artificial-intelligence)
- [Aged Care Roster Optimisation](https://digitalfrontierpartners.com.au/aged-care-rostering-optimisation)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Digital Frontier Partners",
    "url" : "https://digitalfrontierpartners.com.au/news/author/digital-frontier-partners"
  },
  "dateModified" : "2026-10-06T03:32:17.274Z",
  "datePublished" : "2026-10-06T03:32:17.000Z",
  "headline" : "AI Agents Have Moved From Productivity Tools to Security Risks",
  "image" : [ "https://digitalfrontierpartners.com.au/hubfs/AI-Generated%20Media/Images/Cybersecurity%20Team%20Reviewing%20Threat%20Data%20Dramatically.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://digitalfrontierpartners.com.au/news/ai-agents-have-moved-from-productivity-tools-to-security-risks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://digitalfrontierpartners.com.au/hubfs/DFP-Logo.webp"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#organisation",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Melbourne",
    "addressRegion" : "VIC",
    "postalCode" : "3000",
    "streetAddress" : "Level 4, 350 Collins Street"
  },
  "description" : "Digital Frontier Partners provides enterprise technology advisory, AI enablement, workforce optimisation and cybersecurity services, helping organisations align strategy, value and risk.",
  "email" : "contact@digitalfrontierpartners.com",
  "knowsAbout" : [ "Enterprise AI enablement", "Artificial intelligence strategy", "AI governance and risk", "Workforce optimisation", "Cybersecurity", "Technology due diligence", "Digital transformation" ],
  "logo" : {
    "@type" : "ImageObject",
    "contentUrl" : "https://digitalfrontierpartners.com.au/hs-fs/hubfs/DFP-Logo.webp?width=1200&height=342&name=DFP-Logo.webp",
    "height" : 342,
    "width" : 1200
  },
  "name" : "Digital Frontier Partners",
  "telephone" : "+61 1800 288 817",
  "url" : "https://digitalfrontierpartners.com.au/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://digitalfrontierpartners.com.au/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-AU",
  "name" : "Digital Frontier Partners",
  "publisher" : {
    "@id" : "https://digitalfrontierpartners.com.au/#organisation"
  },
  "url" : "https://digitalfrontierpartners.com.au/"
}
```