Research · curated 12 Sep 2026

When AI agents look like attackers: what behavioral telemetry tells us

Coverage timeline

discovered sophos.com primary 12 Sep 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI coding agents are generating adversary-like behavioral telemetry — running low-reputation executables, automating browser tasks, and triggering credential-access rules — creating detection-engineering challenges and alert noise that defenders must learn to distinguish from real attacks.

A joint analysis from The Hacker News and Sophos X-Ops examines telemetry showing that enterprise AI coding agents (Claude Code, Cursor, Codex, and others) increasingly trigger SOC alerts and endpoint behavioral detection rules originally designed for adversaries. AI-related alerts remained only 0.43% of all SOC alerts but grew 685% between February and June 2026, with agent activity frequently mapping to MITRE ATT&CK tactics like Credential Access and Execution.