AI Can Autonomously Hack Cloud Systems, Researchers Warn

Palo Alto Networks has developed an AI called Zealot that can autonomously hack cloud systems. This raises serious concerns for cloud security and detection systems. Organizations need to adapt their defenses to counter these emerging AI threats.

AI & SecurityHIGHUpdated: Published:
Featured image for AI Can Autonomously Hack Cloud Systems, Researchers Warn

Original Reporting

SWSecurityWeek·Eduard Kovacs

AI Summary

CyberPings AI·Reviewed by Rohit Rana

🎯Basically, an AI can hack cloud systems by itself with little help from humans.

What Happened

Researchers at Palo Alto Networks have developed an AI system named Zealot that can autonomously perform penetration testing on cloud environments. This proof-of-concept was designed to assess the capabilities of AI in executing sophisticated cyberattacks without human intervention.

The Development

In a test conducted in November 2025, Zealot was deployed in a simulated Google Cloud Platform (GCP) environment. The AI was given a simple instruction: to exfiltrate sensitive data from a database called BigQuery. Unlike traditional hacking methods that follow strict guidelines, Zealot operated under a 'supervisor-agent' model, dynamically adjusting its strategy based on real-time discoveries.

Security Implications

The results were alarming. Zealot autonomously scanned the network, identified vulnerabilities, exploited them to extract credentials, and ultimately accessed sensitive data. In one instance, it even injected private SSH keys to maintain persistent access, showcasing what researchers termed emergent intelligence. This ability to improvise and adapt during an attack poses a significant challenge for current security measures.

Industry Impact

The implications for cloud security are profound. Traditional detection systems, which are built around human attacker behavior, struggle to identify AI-driven intrusions that operate at machine speed. The researchers emphasize the need for organizations to proactively audit their cloud permissions and implement AI-powered defenses to combat these emerging threats.

What to Watch

As AI technology continues to evolve, the cybersecurity landscape will need to adapt rapidly. Organizations must prepare for the possibility that AI systems like Zealot could be used by malicious actors, leading to faster and more effective cyberattacks. The research highlights the urgency for defenders to rethink their strategies and defenses against AI-enabled threats.

🔒 Pro Insight

🔒 Pro insight: The emergence of AI-driven hacking tools like Zealot underscores the urgent need for adaptive security measures that can respond to rapid, intelligent threats.

Related Pings