Advancements in artificial intelligence, particularly agentic AI, are rapidly transforming both legitimate and criminal cyber operations. AI agents now possess the autonomy to interact with external systems, collect information, and execute tasks with minimal human supervision, streamlining routine activities for both defenders and attackers. While these technologies can lower the barrier to entry for less skilled threat actors, they also introduce new challenges, as AI systems require careful instruction and oversight to avoid errors or unintended consequences. The emergence of the first AI-orchestrated cyber campaign marks a significant milestone, signaling increased experimentation and innovation in the use of AI for cybercrime, but also offering new opportunities for defensive teams to leverage these tools for improved security outcomes.
A recent industry report highlights that 97% of cybersecurity professionals now view automation, increasingly powered by AI, as essential to business operations, reflecting a substantial increase in adoption over the past year. Despite this enthusiasm, 96% of organizations still encounter significant obstacles, including technology limitations, lack of trust in automated outcomes, and insufficient time for implementation. The report, based on a survey of 750 senior cybersecurity professionals across major sectors and regions, underscores both the growing reliance on AI-driven automation and the persistent challenges that must be addressed to fully realize its benefits in combating escalating cyber threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SecuritySenses published an analysis describing how cybersecurity teams are using automation and AI to improve efficiency and productivity. The piece framed AI-assisted workflows as a growing operational trend for defenders.
Cisco Talos announced new Snort 3 capabilities in Cisco Secure Firewall that allow detection rules to be grouped by CVSS-based severity and by the age of the associated vulnerability. The update was presented as a way to improve prioritization and simplify rule management for defenders.
Cisco Talos said the first publicly reported AI-orchestrated cyber campaign had been observed, describing it as an early signal of growing experimentation with agentic AI in offensive operations. The report emphasized that AI currently accelerates existing attacker workflows and lowers skill barriers rather than replacing human operators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.