Inside the emergence of the agentic threat actor and what autonomous cyberattacks mean for defence.
Every cyberattack is a sequence of decisions: where to look, what to exploit, which path to take, and when to persist and when to change direction.
Until recently, most of these decisions were made by a person, even when parts of the operation were automated. Attackers have increasingly leveraged artificial intelligence to accelerate individual tasks, from reconnaissance and vulnerability analysis to phishing and malicious code development. But the human operator still largely connected one move to the next.
Agentic AI changes that.
An AI agent can observe the environment, determine its next move, act on the result and adjust when conditions change. Instead of supporting isolated parts of an attack, it can begin connecting the decisions across the operation.
When an AI agent takes on the coordinating role traditionally played by the human attacker, a new kind of cyber operator emerges.
This is the agentic threat actor.
From Automated Actions to Autonomous Decisions
Traditional automation follows a defined path. It performs a task, processes the result and moves to the next predefined step. If something happens outside that path, the process may stop or require human intervention.
An agentic system is driven by an objective rather than a fixed sequence.
It can interpret what is happening, select between different options and determine how best to continue. If one path fails, it can diagnose the issue and try another. If it discovers something unexpected, it can incorporate that information into its next decision.
With traditional automation, the decisions are built into the workflow before it begins. With agentic AI, more of those decisions can be made while the operation is underway.
The difference is not simply speed.
It is the ability to pursue an outcome across a changing environment.
A First Look at an Agentic Attack
JADEPUFFER offers one of the clearest demonstrations of this shift.
Documented by Sysdig in 2026, the operation began by exploiting a known vulnerability in an internet-facing Langflow instance. From there, an AI agent autonomously connected multiple stages of the attack, including credential discovery, lateral movement and database extortion.
At one point, a login attempt failed. The agent identified the problem, adjusted its approach and continued the operation within 31 seconds.
The individual techniques were familiar. The new element was orchestration.
One agent was able to maintain context, make decisions and move through the attack chain without requiring continuous direction from a human operator.
Familiar Techniques. A New Cyber Operator
The emergence of the agentic threat actor does not reinvent the mechanics of cyberattacks. Vulnerabilities still need to be exploited. Credentials still need to be discovered. Systems still need to be accessed.
What changes is the intelligence connecting these actions.
An agent can coordinate multiple tools, retain context throughout an operation and adjust its approach as new information emerges. Specialised agents could also work together across reconnaissance, infrastructure, exploitation and social engineering.
This introduces a new operating model for cyberattacks: one that can be more continuous, adaptive and scalable.
Sophistication is no longer found only in individual techniques. It is increasingly found in the decisions connecting one move to the next.
The Attack Doesn’t Have to Stop
With agentic AI, a cyber operation no longer depends on continuous human attention.
A human-led attack contains natural pauses. Someone must review the result of an action, decide what to do next and keep the operation moving. Every additional barrier demands more time, effort and concentration.
This is part of the value of defensive friction. Security controls do more than block individual actions. Together, they can slow an attacker, increase the possibility of detection and make an operation more difficult to sustain.
Agentic AI does not make those controls less important. It changes how the attack responds to them.
An AI agent does not experience fatigue, distraction or impatience as the process becomes longer. When an action fails, it can treat the result as new information, select another path and continue.
The 31-second recovery in JADEPUFFER matters for precisely this reason. The significance was not only how quickly the agent moved. It was that the decision-making process did not stop.
The Next Advantage Is Trusted Autonomy
For defenders, this changes the challenge.
If an attack can maintain context and adjust without waiting for continuous human direction, security operations cannot depend on people manually connecting every alert, investigation and response.
Human expertise remains essential. But it must be supported by systems capable of sustaining attention and moving at the speed of the attack.
The response cannot simply be more automation. It must be intentional autonomy.
Intentional autonomy does not mean giving an AI agent unrestricted control. It means deciding where the agent can act independently, where it must stop and when human authority must take over.
This is what makes autonomy trusted.
Trusted autonomy allows security teams to benefit from machine speed without losing visibility, accountability or human direction.
The next advantage will not belong to the organisations that automate the most. It will belong to those that build the strongest relationship between machine speed and human judgement.
When intelligence becomes autonomous, security must become intentional.









