AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh) — Threadlinqs Intelligence
As of 2026-07-25, AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh) is a medium-severity threat intel threat attributed to Multiple unattributed clusters (STAC6994, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1686 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple unattributed clusters (STAC6994 · FINANCIAL
Sophos' AI Security 2026 Report and BeyondTrust/Phantom Labs research document a 466.7% year-over-year surge in enterprise AI agents alongside a parallel rise in attacks against the OAuth tokens, API
AI agent identities -- OAuth-connected service accounts, API keys, and machine credentials bound to coding assistants, chatbots, and autonomous agents -- have overtaken traditional exploit/PoC-driven vulnerabilities as the primary vector cited in current risk-landscape reporting. Sophos' AI Security 2026 Report (published 2026-07-22) and independent research from BeyondTrust's Phantom Labs team (2026-03-23) both frame this as a governance failure rather than a single software flaw: enterprise AI agent deployment grew 466.7% year-over-year, frequently through low-code platforms and embedded AI features in Microsoft Copilot, Azure AI Foundry, Salesforce, ServiceNow, Jira, and Confluence, without centralized identity governance, alert coverage, or least-privilege scoping. In many environments studied, AI agents operate with administrator-equivalent privileges and, unlike static service accounts, can inherit user permissions, call APIs autonomously, and act across systems without an interactive login to anchor detection.
Sophos' most concrete evidence is the STAC6994 cluster: analysts observed a threat actor running a software-development operation inside a compromised network using approximately 12 AI agents to author and test attacks against endpoint protection products (Sophos, CrowdStrike, Microsoft Defender), producing nearly 80 attack modules and more than 70 distinct evasion techniques in days -- work Sophos CTO John Peterson described as AI functioning for the first time as a demonstrated 'operational force multiplier' for an intrusion.
This risk is not hypothetical elsewhere in the ecosystem. The 2025 UNC6395/Salesloft-Drift campaign -- still cited as the canonical AI-agent-identity case study in 2026 reporting -- stole OAuth/refresh tokens from the Drift AI chat integration via voice-phishing of Salesforce administrators, and pivoted through 700+ downstream Salesforce, Slack, Google Workspace, AWS, Azure, and OpenAI-connected tenants before Salesloft and Salesforce revoked all active tokens. In 2026, the NadMesh botnet operationalized Shodan-powered scanning against exposed self-hosted AI/MCP infrastructure (Ollama, Langflow, ComfyUI, Open WebUI, Gradio, n8n) with 20+ exploitation vectors, CISA added a Langflow IDOR to its Known Exploited Vulnerabilities catalog after in-the-wild exploitation of 7,000+ exposed instances, and JADEPUFFER became the first documented ransomware operation run end-to-end by an autonomous LLM agent. Across these campaigns, the consistent root causes are broad or 'Allow All' OAuth scope grants that persist after tool removal, unauthenticated internet-facing AI/MCP servers, and a lack of behavioral baselining for what 'normal' AI agent API activity looks like -- enabling stolen-token traffic to blend in with legitimate usage.
No CVE, CVSS score, or single PoC applies to this item; it is a documented, evidence-backed risk-landscape trend spanning multiple named vendors, named threat clusters, and multiple corroborated 2025-2026 incidents, assembled here as an aggregate threat-intelligence record rather than a single-vulnerability advisory.
Weaknesses (CWE)
CWE-287, CWE-306, CWE-798, CWE-863, CWE-918, CWE-269
Target sectors: technology, finance, government administration, health, professionalservices, retail, softwaredevelopment
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1595.002, T1588.002, T1584.001, T1566.004, T1195.002, T1190, T1133, T1059.001, T1098, T1078.004