Google Threat Intelligence Group's Q3 2026 AI Threat Tracker describes a financially motivated actor who compromised a victim's cloud environment, then used an AI coding chatbot plus markdown agent playbooks to plan, build, and run a mass credential-harvesting campaign in under six hours — compromising thousands of third-party credentials.

The agents didn't just draft code. They ran the scan pipeline, troubleshot failures, and rotated IPs, with outbound traffic leaving from the victim's own cloud addresses. The same report notes an exposed "Recon" C2 dashboard managing more than 23,800 harvested secrets, including cloud and AI API keys.

GTIG has not yet seen fully autonomous zero-day pipelines in the wild — the human still started the compromise. Separately, UNC6780/TeamPCP backdoored MCP servers and hid payloads in .claude / .cursor project directories to evade EDR.

For a Bay Area shop the takeaway is blunt: treat AI coding assistants and MCP/project dirs as part of your attack surface. Inventory what's installed, what OAuth/API keys they hold, and whether a compromised workstation can stand up agentic tooling that looks like normal developer traffic leaving your cloud.