Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsAI is making attacks faster and cheaper to run, but the evidence so far shows acceleration of familiar attack steps, not routine, fully autonomous intrusions. Security teams should respond by tightening the basics attackers still exploit, such as exposed services and weak identity controls. They should also govern the AI systems they run themselves, and prepare to detect and contain incidents at a pace manual processes can’t match.
This article separates what threat reports document from what they don’t, then turns the guidance from Google, Microsoft and CISA into a practical order of work.
What AI has actually changed in attacker activity
The clearest picture comes from three sources: Google Cloud/Mandiant’s March 2026 review of 2025, the Google Threat Intelligence Group (GTIG) report from September 2026, and Microsoft’s 2025 Digital Defense Report. All three describe their own telemetry and observations. None is a census of every attack, so treat them as strong signals rather than totals.
From experiments to operational use
Google’s year-in-review describes 2025 as a shift from experimentation toward operational integration. Early uses were mundane and productivity-oriented: translating content, researching vulnerabilities, drafting multilingual phishing lures and helping write code. Later examples were more worrying. The report discusses malware families it calls PROMPTFLUX and PROMPTSTEAL, which query a large language model for code or commands while running. Because the behavior can change from run to run, signature-based detection has a harder job. These are reported observations about specific malware. They don’t show that malware in general is AI-powered.
#1 Best Overall
Faster operations, with a human still involved
GTIG’s September 2026 report adds evidence of agentic and multi-agent workflows, AI-assisted credential harvesting, and attacks aimed at coding assistants, security scanners, AI credentials and proprietary AI assets. Its headline example is a credential-harvesting campaign assembled and executed in under six hours after a cloud-resource compromise. That is a concrete case of human delay being squeezed out of the process.
The same report says GTIG had not observed fully autonomous pipelines for zero-day discovery and network intrusion deployed against targets in the wild. Both statements hold together: operations are getting faster and more automated, but end-to-end autonomous attack capability was unobserved as of that report.
Most observed threats still hit known gaps
Microsoft describes AI-automated phishing and multi-stage attacks, and also adversaries exploiting poorly secured AI workloads and using synthetic media. But it says most observed threats still targeted known gaps such as web assets and remote services. On identity, Microsoft’s 2025 Digital Defense Report found that 97% of identity attacks were password spray attacks. Old identity weaknesses haven’t gone away because new tools arrived.
Rank #2
| Claim | What the evidence supports | What it does not support |
|---|---|---|
| Attackers use AI | Reconnaissance, translation, lure drafting, coding and some runtime malware behavior (Google, March 2026) | That all malware or all attackers use AI |
| Attacks are faster | A credential-harvesting campaign built and run in under six hours after a cloud-resource compromise (GTIG, September 2026) | That this speed is typical of every intrusion |
| Attacks are autonomous | Agentic workflows that reduce human involvement | Fully autonomous zero-day discovery and intrusion in the wild; GTIG had not observed it |
| Basics no longer matter | Nothing supports this | Microsoft reports most observed threats still target known gaps, and 97% of identity attacks were password spray |
Your own AI is part of the attack surface
The speed problem has a second half: attackers aren’t only using AI, they’re going after yours. GTIG’s September 2026 report describes attacks on AI assets and AI-related software supply chains, including coding assistants, security scanners and AI credentials. Google’s year-in-review names shadow AI and lack of AI asset visibility as practical gaps. If nobody can list which AI tools, models, API keys and dependencies exist, nobody can defend them.
How to adapt: a practical order of work
The steps below follow the guidance from Google/Mandiant, Microsoft and the joint agentic-AI guidance announced by CISA on May 1, 2026. The sequencing, and the last item in particular, is editorial judgment built on those sources rather than a published checklist.
1. Get visibility and governance in place
- Inventory approved AI tools, AI workloads, models, the data they touch and a named owner for each.
- Find shadow AI: unsanctioned assistants, browser tools and personal accounts used with company data.
- Track AI-related credentials and software dependencies as assets, since GTIG reports both being targeted.
- Set clear usage rules so staff know what is allowed and where to ask.
2. Keep agent permissions narrow
The joint guidance from CISA and partner agencies recommends “limiting agent autonomy by ensuring agents are not granted broad or unrestricted access—especially to sensitive data or critical systems,” as quoted in CISA’s May 1, 2026 announcement. In practice:
- Give each agent its own identity and the minimum permissions for its task.
- Keep agents away from sensitive data and critical systems unless the use case truly requires access.
- Scale human approval to the impact of the action. Reading a ticket and deleting a production resource shouldn’t share the same approval path.
3. Fix identity and the known gaps first
Given Microsoft’s finding that most observed threats still exploit known gaps, review internet-facing web assets and remote services, prioritize known vulnerabilities, and harden accounts against password spray. The CISA guidance likewise stresses strong identity management and layered defenses. AI-enabled methods make exploitation of weak controls quicker; they don’t make strong controls obsolete.
4. Threat-model and monitor AI systems
CISA and its partners call for threat modeling, continuous monitoring and regular security assessments. For AI systems, scope should include:
- Prompt-based attacks against assistants and agents
- Software supply-chain exposure, including plugins, packages and model dependencies
- Credential theft and privilege escalation through AI tooling
- Unintended agent actions, not just malicious ones
Re-test after meaningful changes such as new tools, new integrations and expanded agent permissions.
Rank #4
5. Use AI defensively, but validate it
Microsoft describes defenders using AI for threat analysis, identifying gaps and automated response. That is worth pursuing, with limits. Test detections against realistic scenarios, keep human oversight over consequential actions, and make sure your team can explain and trust the procedures the automation follows.
6. Prepare to respond at machine speed
If a campaign can go from a cloud compromise to harvested credentials in under six hours, a response plan that depends on a Monday morning meeting is too slow. Before enabling automation that can suspend accounts or change systems, decide:
- Who may authorize containment, and who can do so out of hours
- How compromised accounts and credentials, including AI service keys, are revoked and recovered
- Which automated actions are reversible, and which need a human first
- How often incident exercises run, and whether they include an AI-assisted attack scenario
Governance-first or AI-tooling-first?
Teams often frame the choice as buying AI security tools versus building governance. The cited guidance doesn’t rank vendors or approaches, but you can compare any strategy on five axes drawn from it:
| Axis | Questions to ask |
|---|---|
| Foundational coverage | Does it address exposed services, identity weaknesses and AI assets? |
| Agent control | Can you limit agent identity, permissions and require human approval? |
| Visibility | Can you monitor across AI systems and the software supply chain? |
| Testability | Can you test detections and response procedures, not just deploy them? |
| Fit | Does it match your risk posture and the staff you actually have to run it? |
A tooling-first approach tends to score well on visibility but can leave agent permissions and response authority undefined. A governance-first approach covers control and fit, but without monitoring it can’t show whether the rules are followed. For most organizations the answer is governance and identity work first, then tools that make those controls measurable.
Limits of the evidence
These findings come from vendor and government sources reporting their own telemetry or guidance, and the research was current as of early October 2026. Attacker tactics shift quickly, so a statement such as “not observed in the wild” can change with the next report. Check the latest GTIG, Microsoft and CISA publications before making budget decisions on the basis of any single figure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

