With AI-powered cyberattacks accelerating, defenders must adapt
According to Google’s latest threat intelligence assessment, AI is beginning to reshape how cybercriminals operate. The latest findings point to a future where attacks are increasingly automated, adaptive and capable of evolving at machine speed.
Google’s recently released AI Threat Intelligence Assessment for Q2 2026 highlights several emerging trends, including increased supply-chain risks, manipulation of large language models (LLMs), and the growing use of agentic AI systems by threat actors. The report is available through Google Threat Intelligence. Rather than creating entirely new forms of cybercrime, AI appears to be dramatically increasing the speed and scale at which existing attacks can be conducted. The result could be a fundamental shift in the balance between attackers and defenders.
From assistance to autonomy
For several years, cybercriminals have used AI tools to improve productivity. Generative AI has helped create phishing emails, generate malicious code and accelerate reconnaissance activities. However, researchers are increasingly observing a transition from AI-assisted attacks to AI-directed attacks. According to Google Threat Intelligence, cybercriminals are beginning to integrate AI into broader attack workflows, allowing systems to make decisions and execute actions with minimal human intervention.
Nick Tausek, Lead Security Automation Architect at Swimlane, believes this development is particularly significant, as he tells Digital Journal. “Attackers are moving beyond using AI as a productivity tool and starting to give it control over larger portions of an attack.”
The key change is the emergence of agentic AI, systems capable of carrying information and context from one stage of an attack to another. Traditionally, cyberattacks have involved multiple discrete stages. An attacker performs reconnaissance, identifies vulnerabilities, gains access, establishes persistence and then moves laterally through systems. Human operators typically oversee each phase and make decisions when obstacles arise. Agentic systems can increasingly perform these transitions independently.
As Tausek says: “Agentic systems can now carry intelligence from reconnaissance into exploitation and post-compromise activity, adjusting tactics when something fails without waiting for a human operator.”
Machine-speed adaptation
One of the most concerning aspects of AI-driven attacks is adaptability. Unlike conventional attack tools that follow predefined scripts, agentic AI systems can analyse results and modify their behaviour in real time. This means that if a phishing campaign underperforms, the system can generate new lures. If a vulnerability proves ineffective, the attack can pivot towards a different technique. Infrastructure, domains and attack paths can be altered dynamically while pursuing the same objective.
For defenders, this creates a significant challenge. Signals that might previously have appeared connected may now seem unrelated because the attack continuously changes form.
According to Tausek, organisations need defensive platforms capable of maintaining continuity across investigations rather than relying on isolated alerts generated by individual security tools: “The AI SOC needs that same continuity. Agentic AI should connect signals across tools, preserve investigative context and adapt response as new evidence emerges.”
In practice, this means security operations centres increasingly need automation that can process and correlate large volumes of security data while allowing analysts to retain decision-making authority.
Another trend highlighted by Google’s assessment is the growing importance of supply-chain risk. Modern organisations rely on extensive interconnected ecosystems of software libraries, open-source components, cloud services, APIs and third-party vendors. As a result, attackers can often achieve greater impact by compromising a trusted supplier than by targeting individual organisations directly.
This comes amid concerns around software dependencies, which have demonstrated how a single successful intrusion can affect thousands of organisations simultaneously. AI may make such attacks easier to scale.
Automated reconnaissance systems can rapidly identify dependencies, map software relationships and uncover vulnerable links within supplier networks. This capability could increase both the frequency and sophistication of supply-chain attacks. For businesses, third-party assurance, software bills of materials (SBOMs) and supply-chain visibility are likely to become increasingly important aspects of cyber resilience.
AI is not creating new attacks
Despite growing concern, some cybersecurity experts caution against overstating AI’s novelty. Cris “Space Rogue” Thomas, Security Advocate at Semgrep and former member of the influential hacker group L0pht Heavy Industries, argues that AI is not introducing fundamentally new attack methods.
Instead, the technology is removing human limitations. “This tells me AI isn’t inventing some magical new attack vector; it’s removing the slowest component from the attack chain: the human,” Thomas observes.
Historically, even skilled attackers have faced constraints imposed by human attention spans, work schedules and technical expertise. AI changes that equation.
Thomas says: “Attackers are starting to hand reconnaissance, troubleshooting, credential harvesting, and exploitation to agents that don’t sleep, don’t get bored, and don’t need to Google error messages.”
This observation neatly summarises the challenge facing security teams. Existing vulnerabilities remain the same, but the rate at which those vulnerabilities can be discovered, analysed and exploited may increase dramatically. Cybersecurity strategies developed over the past two decades have largely assumed adversaries operate at human speed. Security analysts investigate alerts, perform triage and coordinate responses manually. Even sophisticated security operations centres frequently depend on people moving information between tools and systems.
Thomas believes this long-standing assumption may soon be tested. “We’ve spent decades building defences around human-speed attacks; machine-speed attacks are going to find out just how many of those assumptions were load-bearing.”
If attacks increasingly occur at machine speed, organisations may need to rethink incident detection and response processes. Activities that currently require minutes or hours could become too slow. This does not necessarily mean fully autonomous defence systems are the answer. Instead, it highlights the need for greater automation in data collection, threat correlation and routine response activities. The cybersecurity industry is already responding. Platforms using AI-assisted security analytics, automated playbooks and extended detection and response (XDR) technologies are increasingly being adopted as organisations attempt to reduce response times and improve visibility.
With AI-powered cyberattacks accelerating, defenders must adapt
#AIpowered #cyberattacks #accelerating #defenders #adapt