Back to Blog

AI Is Attacking and Defending Your Network

Srishti GoelOctober 1, 202617 min read

The 2026 Cybersecurity Reality Check

In September 2025, an AI agent broke into networks belonging to roughly thirty organizations. It scanned for weak points, wrote its own exploit code, pulled credentials, and sorted through what it found, all at a pace no team of humans could match. A person was steering the operation, but only for a fraction of the work. Anthropic later confirmed that the AI itself carried out somewhere between 80 and 90% of the intrusion.

That case did not involve a rogue robot or a Hollywood-style AI takeover. It involved a state-linked group that jail broke a coding assistant, broke the attack into small tasks, and let the model run. It is the clearest sign yet that the conversation about “AI in cybersecurity” has moved past hype. In 2026, AI is genuinely on both sides of the fight, and understanding how it is used on each side is quickly becoming a basic requirement for running a network, not a nice-to-have.

This blog walks through what AI-driven attacks actually look like right now, what AI-driven defense can realistically do about them, and where humans still need to be firmly in the loop.

The New Battlefield: How AI Powers Modern Cyberattacks

AI has not invented new categories of attack. Phishing is still phishing, ransomware is still ransomware, and vulnerability exploitation is still vulnerability exploitation. What has changed is speed, scale, and polish. Tasks that once needed a skilled operator and several hours now take minutes and can run in parallel across hundreds of targets.

Automated Vulnerability Discovery and Exploitation

The gap between a vulnerability becoming public and someone actively exploiting it has been shrinking for years. AI has accelerated that trend sharply. Research compiled by the Cloud Security Alliance found that AI systems can now generate working exploit code for a disclosed CVE in ten to fifteen minutes, and that a framework built specifically to test these reproduced, verified exploits for roughly half of all CVEs published in 2024 and 2025.

Real incidents back this up. When the React2Shell flaw (CVE-2025-55182) was disclosed in late 2025, active exploitation attempts followed within days, and CISA added it to its Known Exploited Vulnerabilities catalog by early December. CVE-2025-0282 affected Ivanti Connect Secure and had already been exploited in a limited number of appliances when Ivanti disclosed the vulnerability in January 2025. Research published later in 2025 also demonstrated how LLM-based pipelines can automate the creation, refinement, and validation of exploit environments for known CVEs. Synack reported that its customers reduced average mean time to remediation by 47% across severity levels in 2025, showing that remediation practices are also accelerating as exploit windows shrink.

What to do about it: Stop treating patch cycles as monthly or quarterly events. Move critical and high-severity CVEs into an emergency patching lane with a same-week target, and pair that with continuous external scanning so you know about exposed assets before an automated scanner does.

AI-Driven Phishing and Hyper-Personalized Social Engineering

Phishing used to have tells: awkward grammar, generic greetings, odd formatting. AI has mostly erased those signals. A KnowBe4 analysis of email traffic between September 2024 and February 2025 found that over 82 percent of phishing emails showed some use of AI, and that more than 76 percent of campaigns used AI-generated variations specifically to slip past filters that rely on matching known patterns.

The content is also more targeted. Instead of a generic “your account has been suspended” email, AI tools can pull public information about a specific employee, their role, their manager’s name, and recent company news, then generate a message tailored to that one person in seconds.

What to do about it: Shift security awareness training away from “spot the bad grammar” and toward verification habits, confirming unusual requests through a second channel, regardless of how legitimate the message looks or sounds. Pair that with email security tools that score behavior and context, not just known-bad signatures.

The Rise of Real-Time Voice and Video Deepfakes in Corporate Breaches

Deepfakes deserve their own mention because they attack the one thing employees have been trained to trust: seeing and hearing a real person. In March 2025, a finance director at a multinational firm in Singapore joined what looked like a routine video call with senior leadership. Every face and voice on that call was AI-generated, and the director authorized a transfer of roughly $499,000 before anyone realized the executives on screen were not real, as reported by Brightside AI. The attackers reportedly initiated the video call themselves, anticipating that the target would want to verify the request that way.

This is not an isolated data point. The FBI’s 2025 Internet Crime Report logged more than 22,000 AI-related fraud complaints with losses exceeding $893 million, and deepfake-enabled voice phishing attempts reportedly rose sharply in the first quarter of 2025 compared to the previous quarter. Researchers also note that victims rarely report these losses, so the real total is almost certainly higher.

What to do about it: Require out-of-band confirmation for any financial transfer request above a set threshold, no exceptions, even if the request came through a video call. A simple callback to a known number closes most of this gap.

Polymorphic Malware and Autonomous Evasion Techniques

Polymorphic malware changes its own code to avoid signature-based detection. AI has made this easier to build and, more recently, easier to run without a human at the keyboard. In November 2025, Google Threat Intelligence Group documented several malware families experimenting with or operationalizing AI in new ways. PROMPTFLUX used Gemini for code regeneration and obfuscation, PROMPTLOCK generated malicious Lua scripts dynamically, and PROMPTSTEAL used an LLM to generate commands during live operations.

The trend went further in 2026. IBM’s X-Force team documented a ransomware group using an AI-built command and control tool during a live intrusion, and by July, Sysdig published an analysis of what it assessed as the first ransomware operation carried out entirely by an autonomous AI agent, from initial access through a known 2025 vulnerability to encrypting more than 1,300 configuration items, with no human typing a single command during the intrusion itself.

What to do about it: Signature-based antivirus alone is no longer enough. Behavioral detection that watches what a process actually does, rather than what it looks like on disk, is the more reliable layer now, and it should sit on every endpoint, not just the ones your team considers high-risk.

Looking at attack categories alone is not enough. Security teams also need to understand what evidence each attack is likely to leave behind and which defensive control should respond first. Table 1 connects AI-enabled attack behavior with observable signals, immediate controls, and the point at which human judgment becomes necessary.

Table 1. From AI-Driven Attack to Observable Security Signal

The key shift is from identifying known malicious files or messages to correlating behavior across identity, endpoint, network, and communication channels.

How AI powers modern cyberattacks through vulnerability exploitation, phishing, deepfakes, polymorphic malware, and agentic intrusions

The Shield: How AI Empowers Network Defense

The good news is that defenders have access to the same underlying technology, and in several areas it is already changing outcomes measurably.

Autonomous Threat Detection and Extended Detection and Response (XDR)

XDR platforms pull data from endpoints, networks, identity systems, and cloud environments into one place, then use machine learning to spot patterns a human analyst would take much longer to connect. Speed matters more than almost anything else here. CrowdStrike’s 2026 Global Threat Report found that the average “breakout time,” the window between an attacker gaining initial access and moving laterally through a network, fell to just 29 minutes in 2025, with the fastest recorded case at 27 seconds. A detection system that takes hours to flag something useful is already too slow.

What to do about it: If your current monitoring still relies on a human reviewing a dashboard once a shift, that gap is exploitable. Prioritize a platform that correlates signals automatically and can act, such as isolating a device, within minutes of a high-confidence alert.

Behavior-Based Baseline Monitoring and Anomaly Detection

This is the concept underneath most modern XDR and identity tools: the system learns what normal looks like for a specific user or device, such as typical login times, typical data volumes, typical locations, and flags anything that deviates. It is a simpler idea than it sounds, and it is often more effective than trying to list every possible bad behavior in advance, since attackers keep inventing new ones.

What to do about it: Make sure baseline monitoring covers identity activity specifically, not just network traffic. Several ShinyHunters-branded SaaS data-theft campaigns tracked in 2026 relied on vishing and credential-harvesting sites to obtain SSO credentials and MFA codes before accessing corporate cloud applications.

Predictive Vulnerability Management and Risk Scoring

Instead of a flat list of every CVE affecting your environment, predictive tools rank vulnerabilities by how likely they are to actually be exploited against your specific setup, factoring in things like public exploit availability, exposure, and attacker chatter. This matters because the CVE count keeps climbing. Synack’s 2025 research tracked over 48,000 published CVEs for the year, a 20 percent increase from 2024, which makes manual triage genuinely impractical at this point.

What to do about it: Move away from patching everything by CVSS score alone. Ask your security team or provider to show you a prioritized list based on exploitability and exposure, and patch that list first.

Automated Incident Remediation and Zero-Touch Response

This is where AI moves from watching to acting. When a high-confidence threat is detected, the system can isolate the affected device, revoke a compromised credential, or block malicious traffic without waiting for a human to click approve. CrowdStrike reports that its AI assistant, Charlotte AI, has cut manual investigation work by roughly 70 percent while maintaining high decision accuracy in production use, based on the company’s own reporting cited in recent coverage of AI-driven ransomware.

What to do about it: Start with automated containment for the highest-confidence alert types only, such as confirmed malware execution, and expand from there as you build trust in the system’s accuracy. Full automation on day one is not the goal; measured automation is.

AI, Automation, and Agentic AI: Knowing the Difference

These three terms get used interchangeably, and that causes real confusion when teams are deciding what to buy or build.

AI refers to a model that can analyze data and make a prediction or classification, such as scoring whether an email is likely phishing.

Automation refers to a fixed, rule-based workflow that runs the same way every time, such as automatically blocking an IP address after five failed logins. It does not learn or adapt on its own.

Agentic AI refers to a system that can plan a sequence of steps toward a goal, use tools, and adjust its approach based on what it finds, largely without a human directing each individual action. This is what made the GTG-1002 espionage campaign notable: the AI was not just flagging suspicious activity; it was deciding what to do next and doing it.

The distinction matters because agentic AI is the category with the least maturity and the most risk, on both sides. Anthropic’s own report noted that Claude occasionally hallucinated credentials or overstated what it had actually found during the attack it was manipulated into assisting, which is a useful reminder that agentic systems, offensive or defensive, are not yet reliably self-correcting.

The Human Element: Why Cybersecurity Teams Remain Indispensable

None of this replaces a security team. It changes what that team spends its time on.

Strategic Oversight and AI Policy Orchestration

Someone still needs to decide what an AI system is allowed to do without approval, what requires a human sign-off, and how those boundaries get reviewed over time. That is a governance function, not a technical one, and it belongs with people who understand both the business and the risk tolerance of leadership. A model that can take autonomous action needs a policy framework around it just as much as it needs good training data.

Addressing False Positives and Model Bias

AI models are only as good as the data and rules they were built on, and they make mistakes in both directions. Too many false positives and analysts start ignoring alerts, which is its own security risk. Too few, and real threats slip through. Human review is still what catches these failure modes and tunes the system over time, which is why “AI-powered” security should be read as AI-assisted, not AI-only.

Single Platform vs. Scattered Tools: A Simplified Look

Many mid-sized companies end up with security tools bought at different times, from different vendors, that do not talk to each other well. AI-driven defense depends heavily on having unified data to work from, so this fragmentation has a direct cost.

Table 2. Single Platform vs. Scattered Tools

This is a big part of why we built Consltek’s managed security approach around bringing detection, testing, recovery, and training together instead of leaving them scattered across five vendors that were never designed to work as one system.

A 3-Phase Roadmap to AI-Ready Security

Getting ready for this landscape does not require ripping out your entire stack at once. A phased approach works better and is more realistic for most budgets. Deploying new security technology does not automatically mean that an organization is ready to move to the next level of AI-enabled defense. Each phase should therefore combine a defined timeline and deliverable with observable evidence that the underlying security processes are actually working. Table 3 extends the roadmap by showing not only what organizations should implement, but also what should be in place before they progress toward greater automation.

Table 3. AI-Ready Security Roadmap: Timeline, Deliverables, and Readiness Criteria

The progression is deliberately cumulative. Automated response should not be introduced before organizations have sufficient visibility and reliable detection processes. Phase 3 is also ongoing rather than a one-time implementation stage because response rules, automation boundaries, and playbooks need to be tested and reviewed as threats and business environments change.

Quick KPI Snapshot

A short list is more useful than a long one here. These are the metrics worth tracking first.

FAQs

How is AI changing cyberattacks?

Attackers now use AI to find vulnerabilities faster, write more convincing phishing messages, and in some cases run entire intrusions with minimal human involvement, as seen in the GTG-1002 campaign. The tactics are familiar; the speed and scale are not.

Can AI replace a human security team?

No, and current evidence supports that. AI models still make mistakes, including hallucinating information, and they lack the judgment to weigh business context, legal exposure, or reputational risk the way a person can.

What is AI-driven defense, in plain terms?

It is security software that learns normal behavior for your network and flags, or in some cases automatically responds to, anything that breaks that pattern, rather than relying only on a list of known bad signatures.

What are the biggest risks of using AI for cybersecurity?

The main ones are false positives that cause alert fatigue, model bias that misses certain threat patterns, and adversarial attempts to manipulate the AI itself, a risk CrowdStrike flagged as increasingly common in its 2026 threat report.

How do attackers use deepfakes against businesses?

They generate realistic fake video or audio of executives to pressure employees, usually in finance roles, into approving transfers or bypassing normal verification steps, as happened in the Singapore case in March 2025.

What does automate incident remediation actually do?

It lets the system take a predefined action, like isolating a device or disabling a credential, immediately after detecting a high-confidence threat, instead of waiting for a person to review and approve it first.

How should a mid-sized business prepare?

Enforce MFA everywhere, train employees on verification habits rather than spotting typos, adopt a platform with built-in behavioral detection, and work with a partner who can prioritize patching based on real exploitability, not just severity scores.

Where This Leaves You

The honest takeaway is not that AI has made networks indefensible. It is that the baseline has moved. Attackers who once needed weeks now need hours. Defenders who once reviewed alerts once a shift now need systems that can act in minutes. Neither side gets to sit still, and the organizations doing well right now are the ones treating this as an operational shift, not a one-time software purchase.

Start with visibility, tighten identity controls, and build response automation gradually where the confidence is high. If you want a second set of eyes on where your environment actually stands against this, get your IT Blueprint, and we will walk through it with you.

Need Expert Help?

Schedule a consultation with our team to discuss your specific security needs.

Book a Free Consultation