惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
爱范儿
爱范儿
Attack and Defense Labs
Attack and Defense Labs
量子位
The GitHub Blog
The GitHub Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Scott Helme
Scott Helme
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 叶小钗
C
Cybersecurity and Infrastructure Security Agency CISA
S
Securelist
S
Schneier on Security
C
Cisco Blogs
B
Blog RSS Feed
Cisco Talos Blog
Cisco Talos Blog
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
Y
Y Combinator Blog
Latest news
Latest news
T
Tailwind CSS Blog
Jina AI
Jina AI
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
C
CERT Recently Published Vulnerability Notes
D
Darknet – Hacking Tools, Hacker News & Cyber Security
L
Lohrmann on Cybersecurity
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
P
Palo Alto Networks Blog
V
V2EX
博客园_首页
D
Docker
T
Threat Research - Cisco Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Vulnerabilities – Threatpost
月光博客
月光博客
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Know Your Adversary
Know Your Adversary
L
LangChain Blog
The Hacker News
The Hacker News
K
Kaspersky official blog
The Register - Security
The Register - Security
NISL@THU
NISL@THU

Vectra AI Blog

Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Why You Need an NDR to Protect Your Modern Network Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI named in Gartner hype cycle for security operations 2025 Vectra AI Vectra AI Vectra AI How Sanofi Detected and Stopped a Cyberattack How MITRE ATLAS Helps Detect LLM Attacks in Cloud AI Detecting Iranian APT identity attacks across hybrid environments Vectra AI Vectra AI Vectra AI Breaking down the axios supply chain incident Vectra AI Vectra AI Who’s Doing What on Your Network? FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access Detecting Compromise After the Axios Supply Chain Attack. Vectra AI Vectra AI Vectra AI AI Is Now the Attack Surface: Why Your Security Stack Must Adapt Fast Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How attackers use Brute Ratel (BRC4) Vectra AI Vectra AI Vectra AI The Cutting Edge: AI’s Inevitable Rise in Offensive Security Vectra AI Is AI the Right Tool to Defend Against Modern Cyberattacks? Vectra AI Vectra AI Vectra AI Turns Out Network Security Is Cool Again – and It’s Called NDR Vectra AI Vectra AI Vectra AI Choosing the Right NDR: Gartner’s 5 Questions Every Security Buyer Should Be Asking Vectra AI Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Identity Threat Detection and Response (ITDR) Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI You Have the Right Tools. So Why Are Attackers Still Getting In? Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Challenges in Microsoft Log Monitoring: Insights for Your SOC Vectra AI Platform Visualizes Multi-domain Modern Attacks with Attack Graphs Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Gartner Security and Risk Conference – Chaos meets Opportunity Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Network Detection and Response (NDR) Presenting the 2025 Vectra AI Scholars Simplify Threat Investigation and Hunting with Pre-built Queries in Vectra Investigate The 2025 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) - Why Vectra AI Stands Tall Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How Black Basta Turned Public Data into a Breach Playbook Play’s New Tactics Bypass Traditional Defenses. Are You Ready? Charting a New Era of Network Security: Vectra AI at the Forefront Unlocking Operational Efficiency: How Vectra AI Drives 40% Gains in SOC Performance and 391% ROI Identity-Centric Attacks: The New Reality for UK Retail CISA Flags Fast Flux as a National Threat: Are You Covered? AI Agents: What Do They Mean in Cybersecurity?
Vectra AI
Zoey Chu · 2026-02-27 · via Vectra AI Blog

AI is changing how attacks are built and executed. What used to take days of hands-on operator time can now be orchestrated by agents that plan, execute, and adapt, with humans stepping in only when the system needs direction. 

At Vectra AI, our open-source research shows what this looks like in practice: MCP-powered, agentic operations that coordinate multiple reconnaissance and action “workers” across a target environment, while minimizing many of the artifacts defenders have historically relied on. 

These attacks change the packaging, not the mission

Even when the operator is an AI agent, the attacker must still achieve an objective. Achieving that objective requires actions and behaviors to be executed that are visible and ultimately detectable from the network.

In almost every real intrusion, the network remains the path where discovery, movement, coordination, and data access happen. Those behaviors are not optional. They are the work. 

What we demonstrated in our research

Our research here and summarized here highlights how MCP-enabled architectures can shift to event-driven, asynchronous operations, where agents connect when needed, execute tasks, and report results, rather than relying on predictable, repetitive patterns defenders have traditionally keyed on.   

Critically, this approach can blend activity into what looks like normal enterprise AI usage, making differentiation harder when benign tools are generating similar AI API patterns.   

We also show how a swarm approach improves offensive capability by running in parallel, sharing intelligence quickly, and continuing the mission even if one agent gets detected. 

The industry evidence is converging

This is not just a Vectra AI hypothesis.

  • MCP-based agentic red teaming: Hiding in the AI Traffic describes an MCP-enabled architecture designed for asynchronous, parallel operations and real-time intelligence sharing, while reducing detectable artifacts. 
  • Agents in real environments: A Stanford-led study evaluating AI agents vs. human cybersecurity professionals on a live university network (~8,000 hosts) reports ARTEMIS placed second overall, discovered 9 valid vulnerabilities, and outperformed 9 of 10 human participants.
  • Real-world escalation: Anthropic reported disrupting what it describes as a large-scale AI-orchestrated cyber espionage campaign where AI performed 80–90% of the work, with human intervention only at a handful of decision points. 

The key point defenders should not miss

AI can automate a significant portion of an attack and increase stealth. But it does not remove the need to operate across the network to make progress.   

That is why detection anchored in network behavior remains durable, even as tooling becomes more agentic and activity becomes harder to distinguish from legitimate AI usage.   

“It’s been proven that agentic AI increases speed and reduces hands-on time for attackers, but it does not remove the need to operate across a network. Actions like discovery, lateral movement, and communication still must happen. AI agents can drive the attack, but it still has to take the same road to get to the goal. Our research shows both that this is where attacks are going and that AI-powered NDR can detect those behaviors and shut attackers down.”

Sohrob Kazerounian, Distinguished AI Researcher Vectra AI

Why the best tool to stop AI attacks is AI-powered NDR

If attacks become faster and more adaptive, defenses must do the same.

The practical implication is straightforward: you cannot defend against agentic attacks by chasing a specific toolchain, prompt style, or malware family. You need detection that generalizes to what attackers must do, regardless of whether those actions are human-driven or agent-driven.

AI-powered NDR is built for that reality because it focuses on the behaviors required to progress an intrusion across the network, even as attacker coordination shifts toward more event-driven, AI-blended patterns.

Vectra AI secures the hybrid network in the face of expanding AI

As AI adoption grows, both by attackers and by enterprises, the outcome Vectra AI delivers is twofold.

First, Vectra AI detects and prioritizes the network behaviors AI agents generate to move an attack forward, so defenders can stop threats.

Second, Vectra AI gives security teams visibility as enterprises adopt AI themselves, so they can monitor internal AI agent activity and AI usage, both sanctioned and shadow, across the enterprise.

AI changes who is driving, and how fast everything moves. Vectra AI lets you see it all, and stop the threats that come with it.

---

References

  1. Vectra AI Research Blog, New Technologies bring new risks: MCP-Powered Swarm C2 (Aug 27, 2025). 
  2. Janjusevic et al., Hiding in the AI Traffic: Abusing MCP for LLM-Powered Agentic Red Teaming (arXiv:2511.15998, Nov 2025). 
  3. Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign (Nov 2025). 
  4. Lin et al., Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing (arXiv:2512.09882, Dec 10, 2025).