Booz Allen Hamilton and a senior Department of Defense cyber official warned that threat actors are using artificial intelligence to compress the cyberattack kill chain and operate faster than most organizations can detect, patch, and respond. The reporting says cybercriminal and state-backed groups are applying large language models and automated tooling to speed reconnaissance, vulnerability prioritization, exploitation, persistence, and scaling across many targets, with one cited example describing the open-source HexStrike framework exploiting thousands of Citrix NetScaler devices in under 10 minutes via a single critical CVE. Defense officials said the same trend is affecting the defense industrial base, where attackers are increasingly combining AI-assisted workflows with techniques such as living off the land and zero-day discovery.
The warnings come as organizations impose stricter controls on AI use after security and operational failures tied to AI-assisted development and deployment. One cited example says Amazon now requires senior approval for AI-assisted code changes by junior and mid-level engineers after an outage and internal concerns over the blast radius of GenAI-generated modifications, while broader reporting points to exposed secrets, vulnerable code, and compromises involving AI platforms. Across the coverage, the common message is that defenders must move toward more automated, AI-assisted remediation and continuous exposure assessment, while preserving expert human review, secure engineering practices, and coordinated vulnerability disclosure to keep pace with machine-speed attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In an interview published on 2026-06-08, MultiCare Health System CISO Jason Elrod warned that AI tools are accelerating vulnerability discovery and exploitation, forcing healthcare defenders to respond in minutes or hours rather than days or weeks. He said healthcare organizations should shift from traditional vulnerability management toward resilience-focused models emphasizing microsegmentation, zero trust, and stronger identity controls, and linked the urgency to the proposed HIPAA Security Rule update.
On March 19, 2026, a senior Department of Defense Cyber Crime Center official warned that AI is likely helping threat actors compress multiple stages of the cyberattack kill chain, increasing both attack volume and sophistication. He urged defense industrial base organizations to proactively assess exposure and highlighted DCISE incident-sharing and the DIB Vulnerability Disclosure Program as defensive measures.
Cofense's Phishing Defense Center disclosed a phishing campaign that abuses LiveChat to impersonate Amazon and PayPal support and steal credentials, MFA codes, credit card details, and other personal data. Researchers said it was the first recorded instance of attackers using LiveChat this way and published indicators of compromise for the malicious emails.
Booz Allen Hamilton released a report arguing that attackers are adopting large language models faster than defenders and can now accelerate reconnaissance, exploitation, persistence, and scaling at machine speed. The report cited examples including Anthropic Claude-assisted attacks and the HexStrike framework reportedly exploiting thousands of Citrix NetScaler devices in under 10 minutes using a single critical CVE.
On March 10, 2026, Amazon required junior and mid-level engineers to obtain senior approval for AI-assisted code changes. The policy followed a six-hour Amazon.com outage and internal concerns about the high blast radius of GenAI-assisted changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcedefensescoop.com
Open sourcecyberscoop.com
Open sourceboozallen.com
Open sourcedarkreading.com
Open sourcetechtrenches.dev
Open sourcenews.risky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.