Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AI can help security teams analyze alerts, detect threats, respond faster and support recovery. It can also help attackers create convincing phishing and social-engineering attempts, while AI systems themselves can be targeted through their data, inputs or model behavior. The practical conclusion is not that AI automatically makes organizations safer or attackers unstoppable: its value and risk depend on the task, the system’s maturity and the security controls around it.
How is AI changing cybersecurity?
AI is adding capabilities to both sides of cybersecurity, but the evidence does not show that it has transformed every attack or that AI defenses reliably outperform conventional security practice. A useful way to understand the change is to separate three questions: what AI can do for defenders, how attackers can use it, and how AI systems can be attacked themselves.
NIST’s Cybersecurity Framework Profile for Artificial Intelligence, NIST IR 8596, describes potential defensive uses and emerging risks. It is an initial preliminary draft dated December 2025, not a final standard. NIST emphasizes that organizations need to keep evaluating whether AI capabilities are mature enough for their particular needs.
Can AI help detect cyberattacks?
Yes. NIST says AI can augment human analysts, enhance detection and response time, and support recovery. Those are opportunities to improve security work, not evidence that an AI system can independently prevent breaches or replace a security team.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Before adopting an AI security capability, assess it against the work it is meant to do and the environment where it will operate. NIST’s profile and adversarial-machine-learning guidance support evaluating:
- Task: Is the tool intended for detection, alert triage, response or recovery?
- Human oversight: Can analysts inspect the output, understand its limits and make the consequential decisions?
- Use-case maturity: Has the capability been evaluated for the organization’s own systems, data and threat environment?
- Data and lifecycle exposure: What information enters the system, how is it handled, and could its training or operating data be manipulated or exposed?
- Security integration: Does it complement existing email and authentication protections, rather than leave those controls unaddressed?
These are practical evaluation questions, not a NIST vendor-scoring system. Keep ordinary security operations in view as well: the cited guidance does not establish that AI replaces patching, access control, backups or incident-response processes.
How are attackers using AI?
AI can help optimize malicious activity, particularly phishing and social engineering. ENISA’s 2025 threat-landscape announcement describes large language models being used to enhance phishing and automate social-engineering activity. NIST’s preliminary profile discusses realistic spear-phishing communications that may use personalized narratives, manipulated audio or video, and convincing malicious websites or links.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
That can make a message harder to judge by tone or polish alone. A plausible voice, familiar details or professional-looking website is not proof that a request is legitimate. NIST also discusses AI-generated malware and the possibility of agents coordinating phases of an attack; these are emerging capabilities discussed in preliminary guidance, not evidence that every such attack is common or that AI caused any particular incident.
What the 2025 ENISA figures do—and do not—show
ENISA’s Threat Landscape 2025 analyzed 4,875 incidents observed from 1 July 2024 through 30 June 2025. These figures describe the report’s EU-focused threat landscape; they should not be read as global rates or as proof that AI caused the incidents. ENISA’s publication page records a version 1.3 revision on 22 September 2026 correcting figures and links, so the revised report is the appropriate reference when reusing the numbers.
| Measure | Reported figure | Scope |
|---|---|---|
| Incidents analyzed | 4,875 | ENISA’s 2025 threat-landscape analysis; incidents observed 1 July 2024–30 June 2025 |
| DDoS attacks | 77% of reported incidents | ENISA’s 1 October 2025 announcement; it said most were deployed by hacktivists |
| Leading intrusion access points | 60% phishing; 21.3% vulnerability exploitation | ENISA’s announcement summary of the threat-landscape report |
| AI-supported phishing | More than 80% | ENISA reported that more than 80% of observed social-engineering activity worldwide by early 2025 was reportedly AI-supported phishing; this is a time-bounded reported figure, not a timeless global rate |
The sector figures in the same ENISA announcement are shares in its list of the top targeted EU sectors for the observed reporting period, not global attack rates.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Sector | Share reported by ENISA |
|---|---|
| Public administration | 38.2% |
| Transport | 7.5% |
| Digital infrastructure and services | 4.8% |
| Finance | 4.5% |
| Manufacturing | 2.9% |
Can AI itself be hacked?
Yes. AI systems introduce attack surfaces involving their inputs, training data, information handling and intended use. NIST’s 2025 Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations organizes attacks by method, lifecycle stage and attacker goal. NIST’s 2024 explainer gives plain-language descriptions of four broad attack families:
| Attack family | What it targets |
|---|---|
| Evasion | An input is changed after deployment to mislead the model’s output. |
| Poisoning | Training data is corrupted to influence model behavior. |
| Privacy | An attacker targets information associated with the model or its use. |
| Abuse | A model’s behavior is misused or circumvented. |
These categories are not limited to one type of model or one moment in its lifecycle. A security review should consider the model, the data it uses and the systems and suppliers around it—not just whether the model produces useful answers under normal conditions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can organizations defend against AI-powered phishing?
AI-assisted messages can be personalized and realistic, so staff training should address more than spelling mistakes and generic greetings. NIST’s preliminary profile points to updated personnel training and integrated email and authentication security measures. For organizations, a practical response is to:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Refresh training with examples of personalized requests, suspicious links and possible audio or video manipulation. Explain how staff should report a doubtful message or request.
- Preserve independent verification for sensitive requests. Verify through a trusted channel already on file rather than relying on contact details or links supplied in the message.
- Maintain integrated email and authentication protections. Treat these as core controls alongside awareness training, not as alternatives to it.
- Include AI systems in security reviews. Examine their data, lifecycle and supply-chain exposure, and decide who is responsible for monitoring and responding to misuse or manipulation.
- Evaluate safeguards continuously. Do not treat a model safeguard as proof that the system is immune to attack.
Are AI defenses foolproof?
No. NIST says current mitigation approaches do not have robust assurances that they fully mitigate adversarial-machine-learning risks. That does not mean defenses are useless; it means organizations should treat mitigations as risk-reduction measures, monitor for failures and avoid making immunity claims.
NIST computer scientist Apostol Vassilev, a co-author of the 2024 guidance, said the publication describes attack techniques and current mitigation strategies, while warning that available defenses lack robust assurances of fully mitigating the risks. The guidance encourages the community to develop better defenses.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteQuick Recap
What should security leaders take away?
- Use AI to augment defined security tasks, and assess whether the capability is mature enough for the organization’s use case.
- Plan for attacks on people as well as software: realistic, personalized phishing may use text, audio, video or deceptive websites.
- Include models, data, lifecycle stages and supply chains in security reviews.
- Keep email and authentication protections, staff training and established security operations in place.
- Assume no single AI safeguard guarantees protection against adversarial attacks.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

