Skip to content

Image: img.helpnetsecurity.com · rights & removal

Executive Summary

Threat actors are utilizing artificial intelligence to accelerate the cybersecurity attack lifecycle, giving them a significant advantage over defenders. This shift is described as changing the physics of cybersecurity, with vulnerability discovery and weaponization time dropping below 24 hours through prompt engineering. Phishing and exploitation against public applications increased significantly during this period, with phishing accounting for 23% of intrusions and public application exploits rising from 15% to 24%. Furthermore, AI enables attackers to personalize social engineering, allowing them to bypass language barriers and deepen credential harvesting inside compromised systems. State actors, including those from China, Russia, North Korea, and Iran, are integrating AI into their operations for tasks ranging from vulnerability searching and malware creation to agentic workflows. Specific examples include malware that searches for secrets within infected machines and experimental ransomware prototypes shipped with prompts alone.

Facts Only

* Vulnerability discovery to weaponization time has dropped below 24 hours.
* The number of tracked CVEs for 2026 is estimated at 72,000.
* Phishing accounted for 23% of intrusions investigated between July 2025 and June 2026, up from 7% the previous year.
* Exploits against public-facing applications rose from 15% to 24% over the same period.
* AI personalizes phishing messages, enabling spear phishing mass operations.
* Attackers harvested more credentials in 52.2% of intrusions starting with valid accounts.
* State actors use AI for searching vulnerabilities and gaining exploitation tips.
* North Korean groups use AI for persona development, social engineering, and malware creation.
* A specific malware instance searched for Claude Code, Gemini CLI, or Amazon Q CLI on infected machines.
* PromptLock ransomware shipped with prompts alone and received runtime scripts from open-weights models.
* Self-spreading worms driven by AI are deemed feasible with current technology.

Full Take

The narrative demonstrates a fundamental shift from human-intensive, slow processes to machine-accelerated exploitation, where the primary bottleneck has moved from discovery to response. The core implication is that defensive capabilities, historically built around identifying known signatures or patching discovered flaws, are being outpaced by an adversarial system capable of generating novel attack vectors and scalable social engineering. The embedding of AI into state-sponsored operations highlights a concerning convergence: AI is not just an efficiency tool for non-state actors but a strategic force being leveraged by nation-states to scale kinetic and information warfare capabilities across the entire intrusion lifecycle, from reconnaissance to deployment. The development of autonomous systems capable of orchestration, as seen with models controlling enterprise environments in simulation, suggests that the future risk lies less in exploiting individual flaws and more in managing the trust placed in automated decision-making within security infrastructures themselves. The focus shifts from patching vulnerabilities to assessing the integrity of the AI agents driving the attack.
Bridge Questions: If operational decisions are increasingly driven by autonomous, AI-orchestrated attacks, what metrics should security defenses prioritize beyond simple vulnerability counts? How can organizational structures adapt to a reality where AI-driven infiltration speeds outpace traditional human response timelines? What are the inherent ethical and governance challenges when national state actors utilize these capabilities for offensive operations against civilian infrastructure?

From the original · Help Net Security

Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap.
Read the full story at helpnetsecurity.com

Sentinel — Human

Confidence

LIKELY_HUMAN (confidence: 0.35)

AI is giving attackers a head start, Microsoft warns | Huntaegis