Security teams are facing a surge in high-severity vulnerabilities, with AI accelerating exploit development and enabling attackers to weaponize flaws more rapidly. According to Intruder's 2025 Exposure Management Index, organizations are seeing a 20% increase in high-severity issues, while also improving their response time to critical vulnerabilities, with 89% fixed within 30 days. The rapid evolution of AI-generated code, cloud sprawl, and shadow IT are contributing to new exposures, and supply chain compromises continue to disrupt critical sectors. Security teams are adapting by maturing their remediation processes and integrating solutions directly into developer workflows, but resource constraints remain a challenge.
At the same time, the enterprise browser has emerged as a major threat surface, with the Browser Security Report 2025 highlighting that most identity, SaaS, and AI-related risks now converge in the browser. GenAI tools are now the top channel for data exfiltration, with 77% of employees pasting data into GenAI prompts—often from unmanaged, personal accounts. Unmonitored browser extensions and new AI-powered browsers are creating parallel attack surfaces that legacy DLP and EDR tools struggle to address. Enterprises are being urged to rethink their security controls to address these evolving risks, as traditional solutions are increasingly inadequate against the pace and complexity of AI-driven threats.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
The Register and The Hacker News published reports highlighting how AI is enabling bad actors and describing emerging browser-based threats facing enterprise security teams. The references indicate a broad industry assessment rather than a discrete breach, victim disclosure, or law-enforcement action.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.