The signal in 30 seconds.
AI does not create a new contest. It accelerates the contest we already had: speed, scale, identity, judgment and control. The strategic question is no longer whether AI enters the security operation. It is whether your defensive multiplier compounds faster than the adversary’s.
Minutes became seconds.
CrowdStrike’s fastest observed eCrime breakout fell to 27 seconds. Human-only workflows cannot consistently compete at that speed.
Attackers log in.
Malware-free activity now dominates many intrusions. Identity, tokens, SaaS and cloud control planes are the battlefield.
AI changes the economics.
It lets a smaller team—or a weaker actor—research, adapt, translate, test and execute across far more targets.
Autonomy needs boundaries.
Defensive AI wins only when authority, evidence, reversibility and human accountability are engineered into the operating model.
AI does not choose a side.
“I run a global SOC inside this arms race every day. The advantage does not go to the organization with the most AI. It goes to the organization that operationalizes it with the most discipline.”
For attackers, AI compresses research, coding, social engineering, evasion and execution. For defenders, it compresses evidence collection, correlation, triage, containment and learning. Both sides gain speed. Both sides gain reach. Only one side needs to be right once.
One AI core. Two force vectors.
COREAMPLIFY · ADAPT · ACT
The offensive curve is bending.
The attacker does not need an omnipotent model. They need a model that removes enough friction from enough steps to make the campaign faster, cheaper and more scalable.
Source: CrowdStrike 2026 Global Threat Report ↗The window is collapsing.
These measurements describe different phases and datasets, but the direction is consistent: the interval between access and material impact is shrinking.
Unit 42: 285 → 72 minutes ↗ CrowdStrike: 29 minutes average; 27 seconds fastest ↗
eCrime breakout
Watch the agent move.
This is not a lab demo.
Hover or tap each file to inspect the attack chain. Every card links to a primary or named research source.
JADEPUFFER
End-to-end agentic extortion.
Sysdig documented an LLM agent executing a complete operation after initial access. The agent adapted when a login failed, rewrote exploit code and continued the chain.
Read Sysdig research ↗FORTIGATE CAMPAIGN
No zero-day required.
A low-to-medium-skill actor used commercial generative AI throughout a campaign that compromised more than 600 FortiGate devices. AI lowered the skill barrier; weak identity and exposed management interfaces supplied the opening.
Read AWS Security research ↗2FA ZERO-DAY
Reasoning found the trust flaw.
GTIG identified a criminal actor preparing a mass exploitation event using a zero-day that researchers believe was developed with AI. The flaw bypassed two-factor authentication through a semantic logic error.
Read GTIG research ↗HEXAGONALRODENT
Developers became the perimeter.
The campaign targeted Web3 developers, using AI-assisted lures and coding workflows to steal from 26,584 wallets found across 2,726 systems.
View reporting ↗GTG-1002
Large-scale operations, limited human intervention.
Anthropic said a Chinese state-sponsored group manipulated Claude Code to attempt infiltration of roughly 30 global targets, with AI executing most tactical operations.
Read Anthropic disclosure ↗SHADOW AGENTS
The insider surface became autonomous.
CSA reported that 65% of respondents experienced AI agent-related incidents in the prior year while 82% discovered unknown agents in their infrastructure.
Read CSA survey ↗Defense can compound too.
The objective is not autonomous security theater. It is reliable coverage: every signal investigated, every conclusion evidence-backed, every action bounded by risk.
Source: IBM Cost of a Data Breach 2025 findings ↗Average breach-cost savings among organizations using security AI and automation extensively. IBM also reported an 80-day reduction in the breach lifecycle compared with organizations without those capabilities.
AI can perform consistent first-pass investigation across the full signal stream and escalate based on evidence.
Identity, endpoint, email, SaaS, network and cloud evidence become one narrative instead of six dashboards.
Reversible automation can suspend sessions, isolate endpoints or challenge identities while a human owns irreversible decisions.
In production SOC workflows, AI-assisted triage can return dozens of analyst hours each week. Treat local benchmarks as operational evidence, not universal market statistics.
Gartner: more than 40% of agentic AI projects canceled by end of 2027 ↗
the denominator.
Not by making every alert important—by making comprehensive investigation economically possible.
Who multiplies faster?
Attacker mode
Cheap variation. Automated recon. Identity abuse. Adaptive tooling. Machine-speed persistence. One successful path is enough.
Defender mode
Full-queue coverage. Cross-domain context. Reversible containment. Human accountability. Every investigation improves the next.
Build the faster multiplier.
Inventory every agent and every authority.
Know what AI exists, which identity it uses, what data it can reach, which tools it can call and who owns its behavior.
Treat identity as the control plane.
Apply least privilege, short-lived credentials, continuous authentication and agent-specific non-human identity governance.
Unify evidence before automating decisions.
AI cannot reason reliably across fragmented truth. Normalize telemetry and preserve provenance so conclusions can be audited.
Automate reversible containment first.
Start where the cost of delay is high and the cost of reversal is low: session challenges, token revocation, endpoint isolation and access throttling.
Red-team the agent, not just the model.
Test prompt injection, tool-chain abuse, memory poisoning, data leakage, runaway loops and cross-agent privilege escalation.
Measure time-to-decision.
Alert volume is not an outcome. Track coverage, evidence quality, containment latency, reversibility, analyst agreement and learning velocity.
The questions leaders are asking.
How is AI changing cyberattacks in 2026?
AI is reducing the time and skill required for reconnaissance, credential abuse, exploit development, phishing, evasion and post-compromise work. CrowdStrike reported an 89% year-over-year increase in activity by AI-enabled adversaries, while Unit 42 measured the fastest quartile of intrusions reaching exfiltration in 72 minutes—down from 285 minutes the year before.
Can AI make a SOC more effective?
Yes—when it is connected to reliable telemetry, bounded authority and accountable human oversight. IBM reported that organizations extensively using security AI and automation saved an average of $1.9 million per breach and reduced the breach lifecycle by 80 days.
Will AI replace SOC analysts?
AI should replace repetitive queue work, not accountable human judgment. The strongest model makes analysts more powerful: AI gathers evidence and proposes actions; humans own risk, exceptions, governance, adversary reasoning and irreversible decisions.
What is agentic ransomware?
Agentic ransomware uses an AI agent to plan and execute multiple stages of an intrusion with limited human direction. Sysdig described JADEPUFFER as the first documented end-to-end agentic ransomware operation, spanning discovery, credential collection, lateral movement and destructive encryption.
What is the biggest AI security risk inside the enterprise?
Unbounded authority. An agent with broad identity privileges, hidden deployment, weak logging and irreversible tools behaves like an autonomous insider. That is why agent inventory, identity controls, tool restrictions and auditability come before scale.
What should a security leader do first?
Inventory agents and identities, unify evidence, automate reversible containment, test adversarial paths and establish metrics for coverage, decision quality and response speed. Governance cannot be a document added after deployment; it must be part of the architecture.
Primary research behind the film.
The multiplier does not pick a winner. You do.
BUILD THE FASTER DEFENSE · CONTROL THE AUTHORITY · KEEP HUMANS ACCOUNTABLE