Field report · 2026 cyber arms race

AI IS THE FORCE MULTIPLIER FOR SECURITY TEAMS AND ATTACKERS

AI is a weapon held in both hands. It multiplies attackers. It multiplies defenders. The winner is whoever multiplies faster.

0%rise in AI-enabled adversary operations
0 minaverage eCrime breakout time
$0Maverage breach savings with extensive security AI
Answer first

The signal in 30 seconds.

AI does not create a new contest. It accelerates the contest we already had: speed, scale, identity, judgment and control. The strategic question is no longer whether AI enters the security operation. It is whether your defensive multiplier compounds faster than the adversary’s.

01 / SPEED

Minutes became seconds.

CrowdStrike’s fastest observed eCrime breakout fell to 27 seconds. Human-only workflows cannot consistently compete at that speed.

02 / IDENTITY

Attackers log in.

Malware-free activity now dominates many intrusions. Identity, tokens, SaaS and cloud control planes are the battlefield.

03 / SCALE

AI changes the economics.

It lets a smaller team—or a weaker actor—research, adapt, translate, test and execute across far more targets.

04 / CONTROL

Autonomy needs boundaries.

Defensive AI wins only when authority, evidence, reversibility and human accountability are engineered into the operating model.

The same weapon. Both hands.

AI does not choose a side.

“I run a global SOC inside this arms race every day. The advantage does not go to the organization with the most AI. It goes to the organization that operationalizes it with the most discipline.”

For attackers, AI compresses research, coding, social engineering, evasion and execution. For defenders, it compresses evidence collection, correlation, triage, containment and learning. Both sides gain speed. Both sides gain reach. Only one side needs to be right once.

The living center

One AI core. Two force vectors.

AI
CORE
AMPLIFY · ADAPT · ACT
Agentic ransomwareAutonomous sequencing across discovery, access, movement and impact.
Credential spray at scaleFaster targeting, testing and adaptation against identity infrastructure.
AI zero-day discoveryReasoning over code and logic flaws that scanners can miss.
Deepfake fraudAuthority and trust manufactured on demand.
Prompt injectionLanguage becomes executable influence across agents and tools.
Autonomous triageInvestigate the full queue instead of sampling the loudest alerts.
Threat correlationJoin identity, cloud, endpoint, email and network evidence.
Faster containmentRecommend or execute reversible controls before impact spreads.
24/7 coverageConsistent reasoning at global scale without queue fatigue.
Continuous learningTurn each investigation into better detections and playbooks.
Attacker multiplier

The offensive curve is bending.

The attacker does not need an omnipotent model. They need a model that removes enough friction from enough steps to make the campaign faster, cheaper and more scalable.

Source: CrowdStrike 2026 Global Threat Report ↗
0%increase in activity by AI-enabled adversaries, year over year
0%of detections were malware-free—valid identities and trusted tools
0%increase in cloud-conscious intrusions overall
0%increase in cloud-conscious intrusions by state-nexus actors
Attack-time compression

The window is collapsing.

These measurements describe different phases and datasets, but the direction is consistent: the interval between access and material impact is shrinking.

Unit 42 · 2024
285 min
Unit 42 · 2025
72 min
CrowdStrike avg.
29 min
Fastest breakout
27 sec

Unit 42: 285 → 72 minutes ↗   CrowdStrike: 29 minutes average; 27 seconds fastest ↗

27sfastest observed
eCrime breakout
Autonomous attack chain

Watch the agent move.

STATUS: AWAITING INITIAL ACCESS
01
Recon
02
Credential theft
03
Lateral movement
04
Encryption
Real incidents · 2025–2026

This is not a lab demo.

Hover or tap each file to inspect the attack chain. Every card links to a primary or named research source.

Agentic ransomware

JADEPUFFER

1,342configuration items encrypted; key was not recoverable
LANGFLOW → CLOUD KEYS → DATABASE DISCOVERY → LATERAL MOVEMENT → ENCRYPTION → DESTRUCTIVE ACTION →  
Sysdig · July 2026

End-to-end agentic extortion.

Sysdig documented an LLM agent executing a complete operation after initial access. The agent adapted when a login failed, rewrote exploit code and continued the chain.

Read Sysdig research ↗
AI-assisted intrusion at scale

FORTIGATE CAMPAIGN

600+devices across more than 55 countries
EXPOSED INTERFACE → CREDENTIAL ABUSE → CONFIG COLLECTION → NETWORK MAPPING → SCALE →  
Amazon Threat Intelligence · 2026

No zero-day required.

A low-to-medium-skill actor used commercial generative AI throughout a campaign that compromised more than 600 FortiGate devices. AI lowered the skill barrier; weak identity and exposed management interfaces supplied the opening.

Read AWS Security research ↗
AI-developed exploit

2FA ZERO-DAY

FIRSTGTIG-observed zero-day believed developed with AI
CODE REASONING → LOGIC FLAW → 2FA BYPASS → MASS-EXPLOIT PLAN → DISRUPTED →  
Google Threat Intelligence Group · May 2026

Reasoning found the trust flaw.

GTIG identified a criminal actor preparing a mass exploitation event using a zero-day that researchers believe was developed with AI. The flaw bypassed two-factor authentication through a semantic logic error.

Read GTIG research ↗
DPRK crypto theft

HEXAGONALRODENT

$12Mestimated stolen across 2,726 infected developer systems in Q1 2026
DEVELOPER LURE → MALICIOUS CODE → WALLET DISCOVERY → CREDENTIAL THEFT → CRYPTO EXFIL →  
Expel / Recorded Future reporting · 2026

Developers became the perimeter.

The campaign targeted Web3 developers, using AI-assisted lures and coding workflows to steal from 26,584 wallets found across 2,726 systems.

View reporting ↗
AI-orchestrated espionage

GTG-1002

80–90%of tactical operations executed by AI across roughly 30 targets
VULNERABILITY DISCOVERY → EXPLOITATION → PRIVILEGE ESCALATION → DATA ACCESS → EXFILTRATION →  
Anthropic · November 2025

Large-scale operations, limited human intervention.

Anthropic said a Chinese state-sponsored group manipulated Claude Code to attempt infiltration of roughly 30 global targets, with AI executing most tactical operations.

Read Anthropic disclosure ↗
Agent governance gap

SHADOW AGENTS

82%of surveyed enterprises found unknown AI agents in their environments
UNSANCTIONED DEPLOYMENT → UNKNOWN IDENTITY → EXCESS PRIVILEGE → DATA EXPOSURE → RESPONSE GAP →  
Cloud Security Alliance · April 2026

The insider surface became autonomous.

CSA reported that 65% of respondents experienced AI agent-related incidents in the prior year while 82% discovered unknown agents in their infrastructure.

Read CSA survey ↗
Defender multiplier

Defense can compound too.

The objective is not autonomous security theater. It is reliable coverage: every signal investigated, every conclusion evidence-backed, every action bounded by risk.

Source: IBM Cost of a Data Breach 2025 findings ↗
$0M

Average breach-cost savings among organizations using security AI and automation extensively. IBM also reported an 80-day reduction in the breach lifecycle compared with organizations without those capabilities.

Investigate the queue, not a sample.

AI can perform consistent first-pass investigation across the full signal stream and escalate based on evidence.

Join weak signals into attack context.

Identity, endpoint, email, SaaS, network and cloud evidence become one narrative instead of six dashboards.

Contain before the clock wins.

Reversible automation can suspend sessions, isolate endpoints or challenge identities while a human owns irreversible decisions.

Return experts to expert work.

In production SOC workflows, AI-assisted triage can return dozens of analyst hours each week. Treat local benchmarks as operational evidence, not universal market statistics.

0 daysfaster breach identification and containment with extensive security AI and automation
0%operator-reported agreement benchmark between AI triage and senior analyst decisions in a defined production workflow
0 hrsoperator-reported analyst time returned per week in a defined production triage workflow
0%of agentic AI projects expected to be canceled by end of 2027 amid cost, value or risk-control failures

Gartner: more than 40% of agentic AI projects canceled by end of 2027 ↗

The physics of the queue
0
alerts per day in a commonly cited enterprise-SOC benchmark; only about 22% investigated by human capacity alone
AI changes
the denominator.

Not by making every alert important—by making comprehensive investigation economically possible.

Benchmark source and context: VentureBeat, January 2026 ↗

Drag the battlefield

Who multiplies faster?

×

Attacker mode

Cheap variation. Automated recon. Identity abuse. Adaptive tooling. Machine-speed persistence. One successful path is enough.

×

Defender mode

Full-queue coverage. Cross-domain context. Reversible containment. Human accountability. Every investigation improves the next.

In dual mode, the page holds both truths at once: AI is an accelerant. Operating discipline determines who benefits.
Six moves for security leaders

Build the faster multiplier.

01

Inventory every agent and every authority.

Know what AI exists, which identity it uses, what data it can reach, which tools it can call and who owns its behavior.

02

Treat identity as the control plane.

Apply least privilege, short-lived credentials, continuous authentication and agent-specific non-human identity governance.

03

Unify evidence before automating decisions.

AI cannot reason reliably across fragmented truth. Normalize telemetry and preserve provenance so conclusions can be audited.

04

Automate reversible containment first.

Start where the cost of delay is high and the cost of reversal is low: session challenges, token revocation, endpoint isolation and access throttling.

05

Red-team the agent, not just the model.

Test prompt injection, tool-chain abuse, memory poisoning, data leakage, runaway loops and cross-agent privilege escalation.

06

Measure time-to-decision.

Alert volume is not an outcome. Track coverage, evidence quality, containment latency, reversibility, analyst agreement and learning velocity.

Frequently asked questions

The questions leaders are asking.

How is AI changing cyberattacks in 2026?

AI is reducing the time and skill required for reconnaissance, credential abuse, exploit development, phishing, evasion and post-compromise work. CrowdStrike reported an 89% year-over-year increase in activity by AI-enabled adversaries, while Unit 42 measured the fastest quartile of intrusions reaching exfiltration in 72 minutes—down from 285 minutes the year before.

Can AI make a SOC more effective?

Yes—when it is connected to reliable telemetry, bounded authority and accountable human oversight. IBM reported that organizations extensively using security AI and automation saved an average of $1.9 million per breach and reduced the breach lifecycle by 80 days.

Will AI replace SOC analysts?

AI should replace repetitive queue work, not accountable human judgment. The strongest model makes analysts more powerful: AI gathers evidence and proposes actions; humans own risk, exceptions, governance, adversary reasoning and irreversible decisions.

What is agentic ransomware?

Agentic ransomware uses an AI agent to plan and execute multiple stages of an intrusion with limited human direction. Sysdig described JADEPUFFER as the first documented end-to-end agentic ransomware operation, spanning discovery, credential collection, lateral movement and destructive encryption.

What is the biggest AI security risk inside the enterprise?

Unbounded authority. An agent with broad identity privileges, hidden deployment, weak logging and irreversible tools behaves like an autonomous insider. That is why agent inventory, identity controls, tool restrictions and auditability come before scale.

What should a security leader do first?

Inventory agents and identities, unify evidence, automate reversible containment, test adversarial paths and establish metrics for coverage, decision quality and response speed. Governance cannot be a document added after deployment; it must be part of the architecture.

About the author

Adam Khan

Adam Khan is VP of Global Cyber Security Operations at Barracuda Networks. He has more than 25 years of cybersecurity and technology experience and leads a global security operations organization of more than 100 people. His work focuses on building modern SOCs, operationalizing AI, improving detection and response, and turning threat intelligence into decisive action.

25+years in cyber and technology
100+people in the global SOC organization
24×7operator-grounded perspective

Explore Adam Khan Cyber

Sources and methodology

Primary research behind the film.

Data-integrity note. A widely circulated claim that “80% of ransomware attacks use AI,” attributed to a MIT Sloan / Safe Security analysis of 2,800 incidents, was later withdrawn after methodological criticism. It is deliberately not presented here as a reliable fact. Likewise, broad claims such as “90% of all malware is polymorphic” vary heavily by dataset and definition and are not treated here as universal market estimates. Operator-reported production benchmarks in this article are clearly labeled and should not be generalized beyond the measured workflow.
Final frame

The multiplier does not pick a winner. You do.

BUILD THE FASTER DEFENSE · CONTROL THE AUTHORITY · KEEP HUMANS ACCOUNTABLE