Artificial intelligence is rapidly reshaping the cybersecurity landscape, enabling both attackers and defenders to operate with unprecedented speed and sophistication. Security leaders and experts warn that AI-driven malware, automated spear-phishing, and adaptive attack campaigns are already outpacing traditional defenses, as highlighted in recent Congressional hearings and industry research. Notably, Google's threat intelligence team has observed adversaries leveraging large language models to generate malicious scripts and obfuscate code, while researchers have documented the first advanced, AI-enabled cyber-espionage campaigns attributed to nation-state actors. At the same time, AI is being used to automate vulnerability discovery, with new agents like ARTEMIS outperforming most human penetration testers in live enterprise environments, and academic teams developing AI systems capable of autonomously defending wireless networks from jamming attacks.
The dual-edged nature of AI is also driving a widening gap between organizations able to invest in advanced security and those falling below the 'security poverty line.' Predictions for 2026 emphasize that AI will lower the barrier for attackers while raising the cost and complexity of effective defense, forcing security and business leaders to rethink resilience strategies. The use of AI in both offensive and defensive operations is fundamentally altering the economics, speed, and scale of cyber conflict, making continuous adaptation and investment in AI-driven security capabilities a strategic imperative for organizations worldwide.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
In the same hearing, experts warned that adversaries are already harvesting encrypted data in anticipation of future quantum decryption. They urged immediate quantum preparedness and said algorithm updates alone will not be enough without broader architectural changes.
Experts from Google and Anthropic testified before the House Homeland Security Committee that AI-driven malware and autonomous attack campaigns are already being seen in the wild. They said AI is lowering barriers for attackers and accelerating operations beyond defenders' response times, especially for smaller organizations and critical infrastructure.
The University of Ottawa team tested the anti-jamming system in Mobile Edge Computing and O-RAN environments, where it showed resilience and rapid response to interference. The results were presented as a step toward stronger digital infrastructure and spectrum intelligence.
Researchers at the University of Ottawa developed a dual-agent AI system designed to autonomously protect wireless networks from jamming attacks in real time. The system predicts interference and makes rapid decisions to preserve communications.
Recorded Future's Payment Fraud Intelligence team observed a payment fraud incident with overlapping infrastructure and tactics that aligned with Anthropic's disclosed espionage campaign. The analysis connected compromised-card abuse with efforts to access Western AI platforms while masking attacker identities.
Vaishnav Anand presented his work on detecting altered satellite imagery at the IEEE Undergraduate Research Technology Conference at MIT. He warned that manipulated geospatial products could mislead governments and companies that rely on maps for disaster response, planning, and national security.
California student Vaishnav Anand started researching detection of AI-manipulated satellite imagery after being personally targeted by a deepfake. He focused on identifying model fingerprints and structural inconsistencies in altered geospatial images.
The ARTEMIS researchers said the work was conducted under strict safety protocols and responsible disclosure practices, and they released the framework as open source. The release was intended to support broader cybersecurity research and operations.
In a live enterprise-style assessment on a university network with 8,000 hosts, ARTEMIS outperformed nine of ten professional human penetration testers and placed second overall in vulnerability detection. The study also found it operated at much lower cost, though with more false positives and weaker performance on GUI-based flaws.
Researchers from Stanford University, Carnegie Mellon University, and Gray Swan AI created ARTEMIS, a multi-agent AI framework for penetration testing. The system combines dynamic prompt generation and automated triage to find vulnerabilities in enterprise environments.
During the same November 2025 campaign, attackers used Chinese-operated card-testing services to validate compromised payment cards and then attempted to use one for a purchase on Anthropic's platform. Anthropic detected and blocked the fraudulent transaction.
In November 2025, Anthropic disclosed a cyber-espionage campaign attributed to a Chinese state-sponsored threat actor and described as being conducted primarily by an autonomous AI system. The case was highlighted as a highly autonomous AI-orchestrated espionage operation.
A prior research paper in 2021 showed that AI could blend features from one city into another's satellite imagery, illustrating the feasibility of geospatial deepfakes. The work is cited as one of the limited earlier studies in this area.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
recordedfuture.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcetechxplore.com
Open sourcecobalt.io
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.