Friday, September 11, 2026
Home5G newsAI Agents Are Exposing 5G Core Networks to New Security Risks What...

AI Agents Are Exposing 5G Core Networks to New Security Risks What Operators Need to Know

AI agents are quietly rewriting the threat model for 5G core networks from both sides of the fight. As AI Agents Are Exposing 5G Core Networks, researchers just used a chain of AI agents to uncover 84 previously unreported vulnerabilities in open-source 5G core software. Of these, 23 still have no fix. At the same time, security researchers are documenting real-world breaches where attackers used frontier AI agents to compress a two-week intrusion campaign into under 10 hours. For telecom operators, the message is the same from both directions. AI agents aren’t a future risk to plan for eventually. Instead, they’re already changing how fast networks can be attacked, and how fast their flaws get found.

What the researchers actually found

A team at Nanyang Technological University built an AI-driven vulnerability discovery tool called iFinder. This tool runs three AI agents in sequence against 5G core software. One scans code for places where incoming message data is used without proper validation. Meanwhile, a second agent cross-references 3GPP standards documentation to determine whether a suspicious code path is actually a missing security check or a false positive. Additionally, a third writes a working exploit, tests it against a live network, and iteratively rewrites it based on the results.

Turned loose on the software running 4G and 5G phone networks, the agents surfaced 84 security flaws that had gone unreported. Developers have confirmed 83 of them, and 81 now carry official CVE numbers. The most serious finding lets an attacker hijack a subscriber’s data session entirely. It can redirect their network traffic to the attacker instead of the internet. This is a flaw rooted in a bad assumption that persisted as operators moved their cores into cloud environments. In these cloud settings, a misconfiguration can expose an internal interface directly to the open internet.

Two attack paths, one root cause

The research identified two distinct routes into a 5G core, and both trace back to the same underlying problem. This problem is assumptions made in earlier, non-cloud network designs that no longer hold once the core runs in a cloud environment. The first route exploits a misconfigured internal interface left reachable from the public internet. In contrast, the second uses an ordinary phone with a valid SIM to smuggle network control messages inside the data tunnel that carries its own regular uplink traffic. This technique worked successfully against five of the seven open-source 5G cores tested.

AI agent risk snapshot September 2026

Finding Detail
Vulnerabilities discovered by AI agents (iFinder, NTU) 84 total, 83 confirmed, 81 with CVE numbers
Still unpatched 23
Most severe flaw Session hijack attacker redirects subscriber traffic to themselves
Open-source cores vulnerable to SIM-based smuggling attack 5 of 7 tested
Fastest AI-agent-assisted breach documented (Unit 42) Under 10 hours, vs. ~2 weeks for a human red team
New agentic-AI risk categories flagged by McKinsey (telecom-specific) 5, including cross-agent task escalation and untraceable data leaks

The attacker side is moving just as fast

Palo Alto Networks’ Unit 42 recently documented a real-world breach where AI agents functioned as specialized operational workers under an attacker’s direction not deciding strategy independently, but executing technical tasks at machine speed. The compressed timeline let attackers harvest master administrative credentials from a secrets-management platform and reach root-level system access in a fraction of the time a comparable human-led operation would take. Unit 42’s core recommendation for defenders is a shift in mindset: treat AI environments model endpoints, API keys, Model Context Protocol gateways, connected agents as core enterprise infrastructure to be inventoried and secured, not as isolated experimental systems sitting outside normal security scope.

Why telecom specifically is exposed

Speaking at the Ericsson OSS/BSS Summit, McKinsey Partner Duarte Begonha put the industry’s exposure bluntly. Telecom generally lacks the kind of dedicated risk-mitigation processes that banking has developed over decades. This lack persists even as agentic AI starts operating inside core operational workflows. Begonha and McKinsey flagged five agentic-AI risks specific to telecom operations, including cross-agent task escalation. This is when one AI agent requests an action from another by falsely presenting it as coming from a higher authority. There are also untraceable data leaks, where two agents exchange data in a way that obscures the leak from standard monitoring. As Begonha described it, AI agents “are like water, they go where they want to go” and telecom’s operational processes generally weren’t designed with that kind of autonomous movement in mind.

What this means for operators

Cloud migration assumptions need a fresh security review. The most serious vulnerability class in the NTU research wasn’t a flaw in 5G’s design. Instead, it was a gap created when cloud-native deployment changed the trust boundaries that on-premises cores used to rely on. Any operator that has moved, or is moving, core functions into cloud environments should treat interface exposure as an active, ongoing audit item. It should not be considered a one-time migration checklist step.

AI-driven defense has to match AI-driven attack speed. With intrusion timelines compressing from weeks to hours, manual detection and response processes are no longer fast enough on their own. The same agentic techniques enabling faster attacks are also what’s needed to find and patch flaws before they’re exploited. This is exactly the dynamic the NTU research demonstrates from the defensive side.

Agent-to-agent interactions need their own monitoring layer. As agentic AI moves deeper into network operations order orchestration, fault triage, RAN optimization the specific risks McKinsey flagged (task escalation, untraceable data exchange between agents) require visibility. Traditional network security tooling wasn’t built to provide this visibility.

Frequently asked questions

How many 5G core vulnerabilities were found using AI agents? Researchers at Nanyang Technological University found 84 previously unreported flaws using a three-agent AI tool called iFinder. 83 have been confirmed and 81 now carry CVE numbers, with 23 still unpatched.

What is the most serious vulnerability that was found? A session hijack flaw that allows an attacker to redirect a subscriber’s network traffic to themselves instead of the intended destination. This issue is rooted in a misconfigured internal interface exposed during cloud migration.

How fast can AI agents execute a network breach? Palo Alto Networks’ Unit 42 documented a case where AI-assisted attackers compressed an intrusion that would typically take a human red team roughly two weeks into under 10 hours.

What are the specific agentic-AI risks for telecom operators? McKinsey identified five, including cross-agent task escalation (an agent falsely representing a request as coming from a higher authority). There are also untraceable data leaks between cooperating AI agents.

Going deeper

Understanding how cloud-native core architecture, security boundaries, and AI-driven operations intersect is becoming essential knowledge for anyone managing 5G infrastructure. Our 5G Core and 5G Slicing training and full 5G training catalog cover the architecture at the center of this story.


Sources: Help Net Security (NTU/iFinder research, August 2026), Fierce Network (Unit 42 report, McKinsey/Ericsson OSS-BSS Summit commentary), GBHackers. This article is part of our ongoing coverage of 5G core security and AI-driven network operations.


Benefit from Massive discount on our 5G Training with 5WorldPro.com

The most complete and comprehensive 5G course, follow this link for more information

Start your 5G journey and obtain 5G certification

contact us:  contact@5GWorldPro.com

Stay Aware of the last 5G news

Register to our newsletter to receive last 5G news and 5G training details

Follow Us On Linkedin

Most Popular

Receive the latest events

Do you want to participate to this event ?

Get notified about new events