
How AI Is Accelerating Cyber Threats and What Security Teams Should Do Next
AI is not giving rise to a completely new category of cybercrime; rather, it is enhancing the speed, cost-effectiveness, and scalability of existing tactics such as phishing, reconnaissance, malware development, and social engineering.
We’ve had two major wake-up calls – the first was Mythos / Project Glasswing and the second OpenAI’s testing of two models escaping containment, gaining internet access and then compromising Hugging Face to “steal the answers” to the test it had been given.
In both cases, the reaction to cases of AI-accelerated cyber threats have been serious with and panic often close behind.
This article will break down the impact of both, as well as the overall evidence we have of how cybercriminals are using AI in various ways and how your business can adjust its strategy to manage these risks.
Table of Contents
Good Morning – This is Your Wakeup Call
As mentioned, the capability of newer LLM models in 2026 (starting with Anthropic’s Mythos but soon followed by OpenAI and others) to identify bugs in code, develop exploits for them and in some cases even write patches for them has led to what’s been called the Bug-Calypse.
In practice this has played out through vastly increased patch volumes from the tech giants, Microsoft for example patched over 600 vulnerabilities in July 2026, a record month.
However, only about 30% of breaches are due to unpatched software vulnerabilities, so it’s best to adopt a balanced response to AI code scanning highlighting years of technical debt due to writing secure code not being top priority.
In summary – patch faster, scan your own in-house source code yourself before attackers do, harden important and internet facing systems and invest in monitoring so you can catch intruders quickly.
The ExploitGym Incident: A Containment Failure
A second wake-up call came from OpenAI’s testing of two LLM models in ExploitGym, where the models were run in an isolated environment.
It found a zero day exploit in a component that was part of the sandbox (JFrog), exploited this to obtain internet access and then hacked Hugging Face, a model hosting company, to find the answers.
Hugging Face in turn wrote a blog post about their defense efforts, including the fact that due to the volume of activity they were sure it was agentic AI based, as well as when they tried to use a frontier model to defend themselves it wouldn’t work due to the inbuilt guardrails.
They had to fall back to a Chinese open weight model for their defense. Only after some time did OpenAI realize that their test had escaped containment, which calls in question their telemetry as well as the quality of their “isolated” environment.
What Recent Incidents Really Show
The takeaway here isn’t “AI escaped containment” and hacked a company independently (no matter what the headlines say), the lesson is better prompting. No AI model is sentient, they don’t “make decisions” in the way we humans do, no matter how much AI companies try to anthropomorphize their creations.
They simply try every tool and avenue available to them to fulfill the request you’ve given them. The attack was very noisy, apparently generating over 17,000 activities in Hugging Face’s network and also would have cost an attacker a lot of money in tokens, thus as long as your telemetry is comprehensive, you’ll spot an attack of this type easily.
Long term (6-12 months in AI time) the lesson is that as models improve in capability, especially as open-weight derivatives with none or minimal guardrails become available to attackers at reasonable cost, they’ll incorporate these into their toolbox, and you’ll need to make sure you have AI based defenses that can act at machine speed, rather than waiting for humans to react.
The Real AI Cyber Risk Is Acceleration, Not Reinvention
AI isn’t a new threat category, rather it can improve existing attacks, making them cheaper, faster and more scalable.
The threat landscape is still phishing (in email, as well as in messaging apps and vishing – voice phishing), credential theft and social engineering. The difference is that AI can craft more tailored phishing messages, in a wide array of different languages, at increased scale and automate testing different variant to see which ones work the best.
Reconnaissance of a target organization through Open-Source Intelligence (OSINT) can be automated to facilitate the attacker knowing all the personal details of an administrator when calling up the help desk in a social engineering attack.
How Is AI Accelerating Cyber Threats?
- AI is lowering the skill barrier: The first way we’ve seen evidence of how AI is accelerating cyber threats is lowering the skill barrier. Coding malware in particular used to require some coding skills, and to do it well, you needed to be a good developer. Today, anyone with an open weight model, or a frontier model with porous guardrails can write functioning code quickly.
- Low costs allow for rapid output: Secondly, using AI for automation means that the cost for each attempt can be near zero, which allows for rapid output.
- AI helps with iterating the attack: A practical example would be creating a set of compelling phishing messages (lowering the skill requirement of social engineering psychology), sending them out to a large cohort of potential victims (low cost) and then verify which message had the best success and iterating on that message further to increase the hit rate.
AI is a force multiplier for cybercrime, helping criminals to scale their operations through automation of research, impersonation, copy and code writing, translation, operational planning and evasion testing.
The dangers of deepfakes, voice cloning, and AI-assisted BEC
AI technologies are rapidly improving, which poses new risks like deepfakes, voice cloning, and AI-enhanced BEC.
Deepfakes use AI to create realistic fake videos or audio that impersonate people. This can lead to misinformation, fraud, and a loss of trust. Voice cloning lets criminals copy someone’s voice using just a few audio samples, which makes social engineering attacks more effective.
AI-assisted BEC involves creating personalized emails that target specific people in a company, making these scams hard to spot.
By understanding these AI-related threats, organizations can better prepare and develop strategies to reduce risks. This way, their defenses can keep up with these evolving technologies.
Reconnaissance at Machine Speed
Attackers used to fall in two camps – those that did research on their targets through LinkedIn information, job postings, previous breached data, GitHub activity etc. and those that simply attacked any business with a generic attack.
Obviously, the former increases the chance that the attack succeeds but costs a lot in time. AI can vastly speed up this process, particularly when it comes to previous data breaches and the information that can be gleaned from them.
AI creates more personalized phishing lures, makes help desk calls to reset credentials more believable, build target lists, figures out cloud and SaaS app usage, identify supply vendors, privileged users and more.
Defending against ai-accelerated threats requires policies around exposed information on websites and also a policy for staff appropriate sharing on social media, including LinkedIn.
It also helps to monitor your Identity Provider (IdP) logs closely and training staff to spot social engineering attacks, including through multiple channels (first a Teams message, then a phone call from the “helpdesk” for example) or where the caller seems to “have all the answers”.
The Guardrail Problem: When Powerful Models Leave Controlled Environments
AI companies have long realized that frontier models are dual use – they can be used for good, as well as for malicious purposes. Hence there are inbuilt guardrails to stop them from developing malicious code or providing instructions for building chemical weapons etc. However, in practice these guardrails have proved too weak and easily circumvented through social engineering against the model, or sometimes so strong that they can’t be used defensively (as in the Hugging Face case).
Guardrails Have Their Limits
Often guardrails are also weaker or non-existent in open-weight, stolen, distilled or jailbroken models, and while these are generally not quite as powerful as the latest frontier models, they’re only 6-8 months behind, and there’s also some evidence that this time period is shrinking.
Why Distillation Matters
Distillation is a huge problem for frontier AI firms as it enables (mainly Chinese) AI firms to effectively create near parity models without the huge initial investment in AI training hardware.
The actual ecosystem that enables hundreds of thousands of prompts and responses to frontier models to be captured and sold to AI firms is fascinating and relies on AI proxies (called transfer stations in China) providing access to models not legally available in China.
How Organizations Can Defend Against AI Attacks
Given this background what should you focus on in response? Unsurprisingly, going back to the fundamentals of cybersecurity is the way forward:
Strengthen identity
Roll out phishing resistant MFA for all users, have strong Conditional Access policies in Entra, apply least privilege access (and maintain it through regular Access Reviews) and control non-human identities (applications, service principals) and AI agent identities.
Modernize email security
Phishing via email remains a stalwart for initial access so implement a strong system with layered filtering, sandboxing for attachments to be inspected, rewriting of URLs (including at time of click, not just when the email is delivered), impersonation protection and make sure your SPF, DMARC and DKIM records are correct.

Change company culture
Training people regularly with phishing simulations is a good start but a more fundamental cybersecurity culture shift is required in most businesses. With AI accelerating cyber threats, that shift needs to reach every part of the business, from leadership to frontline teams.
Security isn’t the cybersecurity team’s sole responsibility, when marketing rolls out a website with sensitive information without consulting IT or when finance uses a third-party SaaS app that’s not integrated those are business decisions that bring cybersecurity risk – thus cybersecurity in an organization is part of everyone’s responsibility.
Make sure your regular training is up to date with new, AI-based attack variants.
Protect collaboration channels
Modern attacks aren’t confined to email, attackers will use QR code links to trick users into moving conversations into WhatsApp or other personal communication channels, and Microsoft Teams or Slack are also popular with attackers, as is voice-based vishing.
Back up Microsoft 365 data independently
Just because Microsoft makes sure your documents and emails are available through redundant storage, doesn’t mean you aren’t responsible for backing up that data, and needing to be able to recover it from immutable storage in case of a ransomware attack.
Use AI defensively but verify it
AI is not just for attackers. SOC teams can use AI tools and agents to respond faster, but full automation still needs human approval because AI can be confidently wrong.
Verification workflows
Whether it’s the finance department changing a vendor’s bank account number for payments, or a help desk resetting credentials for a privileged user, your best defense is clear processes for human verification that take into account not only phishing emails, but also voice or even video-based impersonation.
Don’t Let AI Set the Pace of Your Security
AI is making familiar attacks faster, cheaper, and harder to recognize. Your defenses need the same speed advantage. With Hornetsecurity 365 Total Protection Plan 4, organizations can strengthen Microsoft 365 security with integrated protection across email, collaboration, awareness, permissions, compliance, and backup resilience.
By choosing 365 Total Protection Plan 4, you gain:
- AI-assisted email and user protection: Help stop phishing, impersonation, misdirected emails, and suspicious collaboration activity before they become incidents.
- Continuous security awareness: Prepare employees for AI phishing, deepfakes, BEC, and social engineering with adaptive training and simulations.
- Governance and resilience for Microsoft 365: Manage permissions, reduce exposure, and recover critical data when prevention is not enough.

Ready to defend against AI-accelerated cyber threats? Schedule a demo today to see how 365 Total Protection Plan 4 helps your organization move from reactive defense to integrated resilience.
Conclusion: Defending at the Speed of AI
AI is not creating a new kind of cybercrime. It is making phishing, reconnaissance, malware development, and social engineering faster, cheaper, and easier to scale.
Hornetsecurity’s 365 Total Protection Plan 4 is the integrated solution for every Microsoft 365 tenant to protect against AI-powered cybercrime. It brings advanced email security, AI Recipient Validation, AI Cyber Assistant, Security Awareness, 365 Permission Manager, compliance support, and backup/data protection in a single, easy-to-deploy plan.
AI-accelerated cyber threats do not change the fundamentals, but they do expose gaps in technology, people, and process. The right response is to reduce the attacker’s speed advantage with faster detection, phishing-resistant MFA, integrated email defense, and reliable recovery.
You don’t need to come up with a new way to defend your business. AI-accelerated cyber threats make existing attack paths harder to ignore, so you need to make them harder to exploit, improve visibility so you can spot attacks when they break through, and build stronger resilience so you can recover when the worst happens.
FAQ
How is AI accelerating cyber threats?
The main risk is the compression of timelines, manual, slow processes and 30 day patch windows which don’t cut it in today’s risk landscape.
Can AI generate new malware?
Models with weak guardrails can absolutely be used to create malware but remember, it’s a tool and in the hands of a beginner the results aren’t going to be amazing, but for an advanced developer the speed and scale to compromise could be vastly improved.
What are AI “agents” in cyber threats?
“Traditional” AI is chat based – you ask a question, get a response etc. AI agents are independent where you describe a goal (“find as many exploits as possible in this ExploitGym environment”) and the agent breaks down the task into steps, and completes each one, often with the help of other AI tools or other agents. Attackers can set up numerous AI agents to autonomously complete discrete steps of their attack chain.
How does AI make ransomware more dangerous?
Interestingly, one recent report looked at how malware crews are now using AI chatbots for ransomware negotiation with victim organizations and of course it can be used at any stage of the kill chain
How can organizations defend against AI attacks?
Get the cyber security hygiene fundamentals right, this will protect your organization against any cybersecurity threat, AI augmented or not.
How do cybercriminals use AI for phishing?
Customizing phishing lures to target organizations or even individual targets increases the chance that they’ll fall for it, scaling using automation to larger target sets and translating attacks in to languages where recipients are traditionally less used to these types of social engineering tricks.
