NetFoundry published a report by Philip Griffiths on Unit 42's breach of a public-facing service using an attacker's own AI infrastructure, revealing that the average breakout time from initial foothold to lateral movement is now 29 minutes and the fastest observed case was 27 seconds.
Public source
Publisher name
Public post
Under 10 hours. That's how long it took an attacker to go from a public-facing service to root access — using the victim's own AI infrastructure along the way. Our Head…
Company
NetFoundry
Secure Workload Connectivity without the headaches of site-to-site VPNs and never-ending firewall rule changes
- Industry
- Computer and Network Security
- Location
- Charlotte, US
- Company size
- 51–200 employees
About NetFoundry
NetFoundry helps businesses secure connectivity between components of their widely-distributed workloads, across any set of networks. Founded by the inventors and maintainers of the world’s most-used open source zero trust software, OpenZiti, NetFoundry’s Identity-First Connectivity™ enables zero trust connectivity with no VPNs, no open inbound ports, and no firewall changes. Software and IoT solution providers use it for secure communications with workloads at their customers’ sites. Enterprises secure access to their APIs and agentic AI services in order to avoid any opening that can be leveraged by an attacker. They also use NetFoundry to simplify the operation of hybrid IT/OT segmentation and enable identity-based microsegmentation.
See moreLatest activity
Latest activity from NetFoundry
13 signals
Products & Services
NetFoundry is leading the CSA's upcoming ZeroTrust and Microsegmentation Guidance contribution, covering connection-defined segmentation and AI agents reaching tools, APIs, and infrastructure.
Research & Knowledge
NetFoundry CSO/CMO Mark Jaffe breaks down this week's Reachability Watch and the pattern behind it.
Presence & Recognition
NetFoundry announced that Hugging Face reached a critical milestone in the Hugging Face Hugging Face Hub.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Palo Alto Networks
Palo Alto Networks Unit 42 published an investigation revealing how a threat actor used frontier AI models to compress two weeks of complex intrusion tradecraft into less than 10 hours.
Research & Knowledge
Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 investigated a breach where a threat actor deployed autonomous AI agents to execute an intrusion in under 10 hours.
Research & Knowledge
Wiz
Wiz analyzed 90 days of attack telemetry across AI frameworks, proxies, and agent deployments to find attackers have built AI-native playbooks.
Research & Knowledge
Recorded Future
Recorded Future published its H1 2026 research showing that attackers are mostly using AI to accelerate methods that already work, and vulnerability timelines are tightening at the same time.
Research & Knowledge
Forcepoint