The Cyber Kill Chain Wasn't Built for AI Agents. Here's How I Extended It
A compromised AI agent doesn't need an exploit to do damage. It doesn't escalate privileges or load shellcode. It calls the tools it was already given, with arguments an attacker influenced through a poisoned web page or a malicious tool description. By the time anything looks