October 5, 2026

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

Concerns over AI-powered attacks are top of mind for organizations, as security teams race to keep up with threats operating at machine speed.

According to the latest Dark Reading readership poll, which inquired about themes from Black Hat USA 2026, the topic that mattered most for security teams was “AI-driven attacks vs. AI-powered defenses in the SOC [security operations center],” with 50% of respondents selecting it. A distant second with 22% was “Scaling SecOps with automation, validation, and trusted AI.”

AI-centric research and presentations dominated the cybersecurity conference, most notably a session from OpenAI that detailed the preliminary findings of its investigation into the Hugging Face hack. Other sessions examined how AI tools are supercharging cyber-fraud operations as well as the continued threat of prompt-injection attacks for AI-powered Web browsers.

But the one topic that appeared to be on everyone’s mind at Black Hat was the rise of AI-driven attacks, and how threat actors are taking advantage of both the speed and the automation that these new tools provide. Can security teams keep up with these newly armed adversaries?

AI Triggers Rapid-Fire Vulnerability Exploitation

The rapidly shortening time frame between a vulnerability’s public disclosure and subsequent attacks has never been clearer, as exploitation of several critical, high-profile flaws recently has commenced within hours of public disclosure rather than days or weeks. That shrinking window, experts say, is heavily driven by large language models (LLMs), particularly the frontier models that have demonstrated a deft ability to identify new vulnerabilities.

The incredible advancement of AI is helping researchers discover more vulnerabilities, as demonstrated by last month’s insanely large Patch Tuesday, and the tools are also helping threat actors analyze patches to develop exploits for those flaws.

poll-2026-blackhatthemes.png

“Attackers are weaponizing vulnerabilities much more quickly,” says Ensar Seker, CISO at SOCRadar, and it’s put security teams in the unenviable position of having to carefully prioritize and patch a select number of vulnerabilities out of hundreds being disclosed.

“Organizations, therefore, cannot treat Patch Tuesday as a simple ‘deploy everything immediately’ exercise anymore,” Seker says, because of the sheer volume of CVEs and the unforeseen side effects that some patches will inevitably introduce in some environments.

“AI has significantly lowered the bar for understanding what patches do, even if the vendor doesn’t tell us,” says Benjamin Harris, founder and CEO of watchTowr, referring to the recent NetScaler zero-day vulnerabilities and Citrix’s lack of communication regarding the threat.

Security through obscurity has “always been questionable,” he says, but it’s especially so now in the AI era. Attackers can use LLMs to quickly figure out what a software update has patched (perhaps silently), without having to wait for a public disclosure, let alone full technical details.

Joe Toomey, vice president of underwriting security at cyber insurer Coalition, says AI has “100%” increased the pace of exploitation, and companies need to be aware of and responsive to that shift.

“We see the increase in the number of published vulnerabilities, and we see the increase in the ones that rise to the level of ‘we need to take action and notify policyholders,'” he says. “We can’t rely on frontier model guardrails or the embargoing of the technology, because it’s out there with open-weight [models].”

Agentic Attackers Equal Relentless Adversaries

As if the speed provided by AI wasn’t enough of an issue for security teams, threat actors are also using models to automate their campaigns. And that may represent a more pressing threat because unlike human hackers, malicious agents don’t require rest, don’t go on vacation, and don’t throw in the towel.

An Omdia report published this summer, “Next Generation Offensive Security Strategies Grant Defenders the AI Advantage,” showed 32% of organizations surveyed said the emergence of AI-powered automated attacks has had the greatest impact on offensive security strategies such as penetration testing and red-teaming. Meanwhile, 25% of organizations pointed to the increased speed of exploitation as the trend that has influenced their offensive security strategies the most.

“AI-powered automated attacks coming in as the top concern and impact on offensive security strategies brings a pragmatic view to the new look of the attackers,” says Theresa Lanowitz, a principal analyst at Omdia. “An AI-powered automated attack is relentless, it never gives up, and never stops looking for ways to attack.”

Agents, she warned, will explore every possible avenue to reach their goal. And that poses additional challenges for security teams; Lanowitz says Omdia’s research shows only 25% of organizations have complete visibility into their attack surface and can account for 100% of their data and assets in real time. You can’t defend the avenues that you don’t know about.

Justin O’Leary, an independent security researcher, notes that in the Hugging Face breach, OpenAI agents followed familiar attack paths but in a compressed timeline. “Nothing exotic, just faster,” he says.

One of the biggest advantages that AI automation provides for threat actors, he says, is the ability to quickly map out the identity and access management policies for a given account, as well as the trust relationships between the managed services in it. “These are time-intensive tasks that would typically take weeks,” O’Leary says.

Defenders Must Match Machine Speed of Cyberattackers

How can security teams fend off the faster, automated attacks of today’s threat landscape? Omdia research shows that 85% of organizations are increasing their spending on offensive security, which Lanowitz says indicates that cybersecurity leaders understand the need for a more proactive position. “Keeping ahead of the adversary through the use of AI is where security teams are headed,” she says.

Being proactive is especially important for the kinds of attack chains and flaws that don’t cause any odd behavior and therefore won’t trigger alerts. “Defenders can use AI to map out and verify who can actually do what in their environment before some ill-intentioned person does,” O’Leary says. “Faster triage alone won’t catch them.”

For vulnerability management, Toomey says automatic patching is worth considering but only if it’s carefully implemented by mature organizations. “You can build a mature process with release rings, and you can allow people to subscribe to early access,” he says. “And you can roll patches out in a controlled fashion and monitor the health of the systems that have been updated and make sure there’s nothing anomalous coming back before you push it out further.”

But auto-patching isn’t for everyone, and it will take time for organizations to optimize AI for defense and figure out how to stay ahead of faster exploitation and automated attacks, he acknowledges: “In the long, long-term horizon, maybe we’ll come out better. But in the short term, there’s going to be pain.”

Read more about:

CISO Corner

Originally published on Dark Reading