Agentic attacks demand Agentic defenses: Here’s where Asia Pacific security teams should start

Agentic attacks demand Agentic defenses: Here’s where Asia Pacific security teams should start

Agentic AI is reshaping both cyberattacks and cyber defence and Asia Pacific security teams must adapt quickly to stay ahead.

Josh Lemos, CISO, at GitLab

Agentic AI is transforming software and security. Recent research found 90% of executives in Singapore expect AI to become the standard for software development within three years with cybersecurity cited as the top concern by 53% of leaders.

This concern is well-founded. Anthropic recently identified what appears to be the first documented AI-enabled espionage campaign making clear that attackers are moving quickly to adopt AI capabilities. Over the past year I have argued that large language models (LLMs) offer defenders a meaningful asymmetric advantage. Already that balance is shifting. Agentic AI systems and the rapid build-out of offensive AI infrastructure have shown threat groups exactly how to scale agent-driven toolchains. Now the advantage sits with them.

This trend shouldn’t come as a surprise. Work from teams such as XBOW and OpenAI’s Aardvark has demonstrated that highly skilled operators can train AI-powered threat-hunting agents that outperform individual analysts. Threat actors now have access to similar capabilities giving them a practical blueprint for running autonomous multi-stage attacks without requiring human intervention at every step.

If organisations in Singapore and across Asia Pacific don’t prepare these agentic attack chains will create serious challenges for security operations. The good news is that the same combination of maturing models automation and workflow orchestration that enables attackers can also be turned to the defender’s advantage.

Security teams can use agentic systems to harden environments accelerate detection and close the window of opportunity before these attacks take hold.

Rising vulnerabilities are turning into active exploits

AI agents have significantly shortened the time between vulnerability discovery and exploitation. A 2024 research paper showed how GPT-4 when provided with CVE descriptions could autonomously exploit real-world one-day vulnerabilities. In fact it successfully did so with 87% of the vulnerabilities tested.

More recently Google has announced that its Big Sleep research has found numerous zero-day vulnerabilities in open-source projects. A collaboration between DeepMind and Project Zero Big Sleep included a multi-phase set of agents designed to discover software vulnerabilities and build working exploits.

While Big Sleep empowered industry security leaders to prevent those exploits from materialising there is no doubt that malicious actors are using the same techniques to compromise targets.

Threat actors are chaining AI agents

Adversaries are breaking down attack phases into separate agentic workloads and using chains of agents to execute each phase autonomously.

For example threat actors are now using AI at every stage of their operations from victim profiling to data analysis and identity creation.

Anthropic’s cyber espionage report found threat actors using AI agents to perform 80-90% of attack operations independently including identifying valuable infrastructure targets discovering vulnerabilities exploiting them and harvesting credentials. Human intervention was required fewer than seven times at critical decision points. Operating at thousands of requests per second AI agents drastically shortened the timeline and the number of people needed to execute the campaign.

Anthropic’s 2025 Threat Intelligence Report also revealed that AI is enabling lower-skilled threat actors to learn and execute more advanced tactics techniques and procedures. Cybercriminals with minimal technical expertise used Claude to develop and sell multiple ransomware variants for US$400-US$1,200 on Internet forums. In this case the criminals relied entirely on AI to implement encryption algorithms and evasion techniques.

Agentic AI has made weaponising exploits cheaper and more autonomous than ever enabling high-volume campaigns targeting companies’ most valuable data assets.

Defending with Agentic AI

Security teams in Asia Pacific must respond in kind. Red teams and defensive practitioners need AI agents that can tap into internal systems and contextual data enabling them to break down complex defensive tasks into smaller workloads and chain them together to find and fix vulnerabilities before attackers exploit them.

For these agents to operate effectively they need a detailed understanding of an organisation’s software environment. This means building the right infrastructure to supply them with relevant data and context. Knowledge graphs which map connections across entire codebases and development workflows offer one practical foundation for Asia

Pacific’s fast-moving Digital Transformation ecosystem.

With access to knowledge graphs agents can blend historical vulnerability data internal institutional knowledge and known security anti-patterns to prioritise threats based on real-world attack behaviours rather than abstract risks.

Agentic defences also strengthen resilience. By breaking down defensive work into detection investigation containment and remediation steps that mirror an organisation’s runbooks AI agents can support the full lifecycle of an incident. That includes everything from initial identification to post-incident analysis helping reduce dwell time and limit impact.

Attackers are already leveraging these tools. Defenders cannot afford to wait.

Browse our latest issue

Intelligent CIO APAC

View Magazine Archive