How do attackers iterate or pivot to expand their control in agentic systems?
For simple applications, a single hijack might be the end of the attack path. But in agentic systems, where AI models plan, decide, and act autonomously, attackers exploit a feedback loop: iterate and pivot. Once an attacker successfully hijacks model behavior, they can: Pivot laterally: Poison additional data sources to affect other users or workflows, scaling persistence.
Iterate on plans: In fully agentic systems attackers can rewrite the agent’s goals, replacing them with attacker-defined ones.
Establish command and control (C2): Embed payloads that instruct the agent to fetch new attack