Organizations and researchers reported that AI is materially reshaping cybersecurity operations, both by increasing the scale of threats defenders must process and by expanding what automated systems can do. Commonwealth Bank said it built its own agentic AI threat-hunting capability because commercial tools were not keeping pace with emerging AI-enabled threats, citing a jump from tens of millions of signals to hundreds of billions and describing repeated phishing infrastructure that appeared to reuse common backend code, sometimes with artifacts associated with AI coding tools. The bank said it is using internally built AI to ingest threat intelligence, analyze it against its own environment, and help junior analysts operate with access to knowledge normally held by senior staff.
Separate reporting and research reinforced the broader operational and strategic impact of AI on security. TechTarget outlined how security leaders are being pushed to justify AI investment through measurable gains in analyst throughput, risk reduction, and cost avoidance, including improvements in MTTD, MTTR, vulnerability remediation, and configuration management coverage. The UK AI Security Institute published testing showing that frontier AI agents are becoming more capable in multi-step cyber-attack scenarios on simulated network ranges, with newer models completing substantially more attack steps and benefiting further from increased inference-time compute. Taken together, the material is not fluff: it documents enterprise deployment, board-level investment considerations, and government-backed evidence that AI systems are improving at complex offensive cyber tasks.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Commonwealth Bank of Australia said it developed its own agentic AI tools for cyber defense because commercial security vendors were not keeping pace with AI-enabled threats. The bank built one agent to correlate threat intelligence with internal environments and another to search for indicators of compromise and generate reports, cutting some threat assessment work from two days to 30 minutes.
TechTarget published an article focused on calculating the return on investment of AI in cybersecurity. No specific discrete real-world incident, breach, or operational event was described in the provided reference.
The UK AI Security Institute published research testing seven frontier AI models in realistic multi-step cyberattack scenarios across a corporate network and an industrial control system range. The study found rapid gains in offensive capability across model generations and with higher inference-time compute, while also noting current limitations in complex ICS tasks and patching an unintended attack path discovered during testing.
Researchers proposed an environment-grounded multi-agent architecture for autonomous penetration testing in robotics environments, using shared graph-based memory to track topology, communications, vulnerabilities, and exploit attempts. In a ROS/ROS2 robotics Capture-the-Flag evaluation, the system reportedly solved the challenge in all five runs while emphasizing traceability and human oversight.
Researchers introduced CTI-REALM, a benchmark for evaluating AI agents on cyber threat intelligence interpretation and security detection rule development using emulated attacks across Linux, cloud, and AKS environments. The evaluation reported results for 16 frontier models, finding Claude Opus 4.6 (High) achieved the highest overall reward and that CTI-specific tools and memory augmentation improved performance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetechtarget.com
Open sourceaisi.gov.uk
Open sourceinfosec.pub
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.