AI-Enabled Cyberattacks: How They Work and How to Defend Against Them

Summary
An explainer on how AI is speeding up and scaling cyberattacks, with examples of agentic operations, pressure on vulnerability patching, and guidance for validating security controls.
Key points
- The article distinguishes AI-assisted attacks from agentic operations, in which AI plans, executes, and adapts across attack stages.
- Anthropic attributed the 2025 GTG-1002 campaign to a Chinese state-sponsored group and reported that Claude Code performed 80–90% of tactical operations across roughly 30 targets.
- Sysdig described JadePuffer as the first known agentic ransomware operation; after a failed backdoor login, its agent corrected the payload in 31 seconds.
- CrowdStrike reported an 89% year-over-year rise in attacks by AI-enabled adversaries, while the article says vulnerability discovery is outpacing human review and patching.
- The article recommends prioritizing vulnerabilities by verified exploitability, continuously testing prevention and detection controls, and triggering validation when threats or environments change.
- It advises automating security validation with human approval at key decision points and maintaining an audit trail.
Article Details
- Topic
- AI-enabled cyber attacks and machine-speed security validation
Vendors
Products
Claude CodeAnthropic attributed the 2025 campaign with high confidence to a Chinese state-sponsored group and reported that Claude Code performed 80–90% of tactical operations across roughly 30 targets.Claude Mythos PreviewIn April 2026, Anthropic reported that Claude Mythos Preview can find zero-days in both open-source and closed-source software with minimal human steering, and in many cases turn them into working proof-of-conceptFortiGatea single actor with limited technical skills use commercial generative AI to compromise more than 600 FortiGate devices across 55 countries in about five weeks, without exploiting a single FortiGate vulnerability.Numi AIIt combines three validation methods, run end to end by Picus Swarm, a set of five specialist agents orchestrated by Numi AI.PaperCutIn September 2026, GreyNoise reported that hundreds of AI agents were used to exploit newly disclosed PaperCut vulnerabilities, compromising at least 440 servers across 395 organizations in 48 countries.Picus Autonomous Exposure Validation PlatformThe Picus Autonomous Exposure Validation Platform was built for this problem.Picus SwarmIt combines three validation methods, run end to end by Picus Swarm, a set of five specialist agents orchestrated by Numi AI.