Surveillance:
Intelligence History

Secret operations, double agents, and the decisions left out of the official version.

Evaluate

Sponsorship confirmed.

AI's Role in Evolving Cyberattack Strategies

Sep 25, 2026
AI's Role in Evolving Cyberattack Strategies

Security leaders are engaged in ongoing discussions about whether artificial intelligence (AI) will create an entirely new class of cyberattacks. However, a more immediate transformation is already taking place: AI has significantly reduced the cost of retrying failed attacks. This shift is evident in the tactics employed by attackers, who can now quickly adjust their strategies after an initial failure.

In a typical scenario, an attacker may gain access to a low-privilege cloud account and attempt to escalate their privileges. If this initial attempt fails, the process that once required extensive documentation, permission checks, and debugging can now be streamlined with AI assistance. The AI can analyze the error, suggest fixes, and initiate new attempts within minutes, effectively shortening the time and skill required for successful intrusions.

Surveillance:
Intelligence History
Evaluate
Cybersecurity Books
Evaluate
World Affairs Books
Evaluate

Sponsorship confirmed.

The evolution of AI's role in cybercrime has been documented over the past few years. In early 2025, Google's Threat Intelligence Group reported that state-sponsored actors were utilizing generative AI for various tasks, including translation and scripting. By late 2025, these same actors were leveraging AI to enhance their malware capabilities, with reports of AI-assisted operations that spanned from reconnaissance to ransom demands. In May 2026, the group identified a two-factor authentication bypass in an open-source tool, attributing the discovery and exploit development to AI assistance.

This distinction between AI-assisted operations and confirmed deployments in the wild is crucial. While the evidence suggests a trend toward AI integration in attacker workflows, the actual prevalence and attribution of these activities remain challenging to ascertain. The direction of this trend indicates that AI is becoming an integral part of the cyberattack process, rather than merely a tool used alongside traditional methods.

Provider guardrails play a significant role in mitigating misuse of AI technologies. Safety measures and abuse prevention mechanisms increase the cost of employing AI for malicious purposes. However, these guardrails are not foolproof. Attackers can still manipulate AI systems by reframing requests or splitting malicious tasks into seemingly innocuous ones, thereby circumventing security policies.

The attack lifecycle is often depicted as a linear process: reconnaissance, access, escalation, and impact. In practice, however, attackers operate in a loop, continuously adjusting their strategies based on real-time feedback from their environment. AI accelerates this loop, allowing both novice and experienced attackers to conduct more experiments in a shorter timeframe.

Adapting Defense Strategies to Attack Dynamics

Defensive strategies should ideally mirror this iterative approach. When an alert is triggered, security teams gather context, form hypotheses, validate scope, and take action. Unfortunately, this process is often interrupted by delays and handoffs, leading to inefficiencies. Alerts may sit unassigned, and critical information can be lost in the transition between teams.

The mean time to acknowledge and remediate alerts often obscures the underlying delays. While an alert may be acknowledged quickly, the subsequent investigation can take hours as analysts sift through various consoles to reconstruct the incident. This latency in decision-making can hinder effective responses to threats.

The functions of a security operations center (SOC) typically include threat intelligence, threat hunting, detection engineering, investigation, and remediation. While these functions are essential, the real challenge lies in the transfer of information between them. Each handoff can result in a loss of critical context, leading to duplicated efforts and missed opportunities for timely action.

For example, consider a scenario where a finance employee logs in from an unfamiliar hosting provider. Despite passing multi-factor authentication, suspicious activity follows, such as the creation of a mailbox rule that forwards emails to an external address. While no single event conclusively proves compromise, the sequence of actions warrants investigation. However, the context that connects these events may not be fully communicated across teams, leading to incomplete assessments.

Final Assessment

To address these challenges, organizations need to adopt a more stateful approach to security operations. This involves retaining evidence and case histories while ensuring that the reasoning behind decisions is preserved. By creating a shared operational memory, security teams can enhance their ability to respond to incidents effectively.

In conclusion, the integration of AI into cyberattack strategies is reshaping the landscape of cybersecurity. As attackers leverage AI to streamline their operations, security teams must adapt by improving their workflows and ensuring that critical context is retained throughout the incident response process. The future of cybersecurity will depend on the ability to maintain a comprehensive understanding of threats and to respond with agility and precision.

Surveillance:
Intelligence History

Secret operations, double agents, and the decisions left out of the official version.

Evaluate
Cybersecurity Books

Threats, defenses, and the human habit of clicking things we really shouldn't.

Evaluate

Sponsorship confirmed.

Recommended for You
AI-Driven Cyberattacks Prompt Calls for Enhanced Security Measures
Intelligence Sep 17, 2026

AI-Driven Cyberattacks Prompt Calls for Enhanced Security Measures

The rise of artificial intelligence is leading to a surge in autonomous cyberattacks, posing significant risks to critical infrastructure…

Surveillance:
Intelligence History

Secret operations, double agents, and the decisions left out of the official version.

Evaluate
Cybersecurity Books

Threats, defenses, and the human habit of clicking things we really shouldn't.

Evaluate
World Affairs Books

Diplomacy, rivalries, and the backstory behind the next international headline.

Evaluate
Intelligence Analysis & Critical Thinking

Books on evaluating evidence, testing assumptions, and building sound assessments. Confidence is not a substitute for a source.

Evaluate
Counterintelligence Case Studies

Nonfiction accounts of moles, deception, and investigations. The warning signs tend to look clearer in the final report.

Evaluate
Diplomacy & Negotiation Books

Books on diplomacy, negotiation, and the work behind an agreement. The handshake is usually the shortest part.

Evaluate

Sponsorship confirmed.