Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI is being used in cybersecurity to find and validate vulnerabilities, help prioritize patches, support incident response, test AI systems, and operate security services. A separate set of reports concerns attackers using AI, which is not the same as authorized defensive research. The 15 examples below come from an AI Weekly index last updated August 30, 2026; the publisher says 13 are in production or have results and 8 have a reported outcome. Those are the index’s counts, not an independently audited survey or a measure of how widely AI is adopted across cybersecurity.

What the 15 deployments show

The cases differ in purpose, maturity, oversight, and evidence. Some describe production use or reported security findings; others are pilots, service announcements, organizational changes, or claims covered by secondary reporting. Their outcomes cannot be ranked on one common performance measure.

Deployment Reported security task What is established in the cited account
Anthropic — Alice Testing and monitoring AI systems The index describes production use to red-team and monitor systems for jailbreaks, prompt injection, and agent misuse; reported August 25, 2026.
Wiz — Red Agent Vulnerability discovery Wiz says its authorized research found a GitHub Actions injection in a public Snowflake repository. The discovery and disclosure are described below.
OpenAI — internal incident-response analysis Log analysis for response The index reports internal model use for log analysis, dated August 14, 2026, citing secondary coverage. Model and version details are not independently established here.
OpenAI — Daybreak Red Vulnerability research The index reports Chrome V8 vulnerability discoveries, citing secondary coverage. No independently verified performance figure is available here.
PortSwigger — HTTP Terminator HTTP desynchronization research PortSwigger describes autonomous generation and testing of research ideas, including authorized testing on sites with a bug bounty program or vulnerability-disclosure policy.
Google — Chrome security work Discovery, validation, triage, and fixes The index reports AI-assisted work and a combined bug count for Chrome versions 149 and 150, based on secondary reporting. The count is not independently verified here.
XBOW — Bing Images testing Authorized offensive-security testing The index reports an autonomous agent found two command-injection flaws that Microsoft later fixed; the entry cites secondary coverage.
Searchlight Cyber — WordPress analysis Vulnerability-chain discovery Searchlight’s account describes multi-agent analysis that found a pre-authentication SQL-injection-to-remote-code-execution chain. Its process and cost estimate are company-reported.
OpenAI — GPT-Red AI-system red teaming and adversarial training The index reports prompt-injection testing and benchmark results from secondary coverage. Any benchmark applies to its tested setup, not to AI systems generally.
Microsoft — cybersecurity organization and response Organizational change The index reports a reorganization tied to AI-assisted vulnerability discovery and response. A reorganization is not itself evidence of a security outcome.
Microsoft — MDASH Windows vulnerability scanning The index describes a multi-model scanning harness and labels it in production; its cited support is secondary reporting.
Cloudflare — Project Glasswing Testing cyber-threat scenarios Cloudflare describes a pilot using Anthropic’s Mythos on Cloudflare infrastructure. It is a pilot, not proof of broad deployment or general system security.
Grimfengxi — reported adversarial use Exploit-code generation The index says Bloomberg reported the group used DeepSeek to generate exploit code. This is a reported adversarial case, not a vendor-confirmed deployment.
US agencies — Gold Eagle Vulnerability intelligence and patch prioritization CyberScoop reported that the federal clearinghouse had begun receiving vulnerability intelligence and prioritizing patches by July 14, 2026.
SoftBank — Patching as a Service Vulnerability assessment and remediation advice SoftBank announced the OpenAI-powered service on June 16, 2026, for Japanese businesses involved in critical infrastructure. The announcement does not establish that all intended customers had onboarded.

How AI is being used to find and validate vulnerabilities

Wiz’s authorized Snowflake repository research

Wiz says Red Agent identified a script-injection vulnerability in a public Snowflake GitHub repository while working through Snowflake’s HackerOne disclosure program. The vulnerability became live on June 18, 2026; Wiz says it reported it on June 23 and Snowflake fixed it that day. Wiz also says its audit logs showed its team was the only actor during the exposure window and that test data was deleted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is an important qualification about AI’s role in the code. In an August 17 update, Wiz said Copilot co-authored a related pull request and marked it all-clear, but it was unclear whether AI assisted with the code change that introduced the vulnerability. The account does not support saying that Copilot wrote the vulnerability.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

PortSwigger’s HTTP desynchronization research

PortSwigger research director James Kettle describes HTTP Terminator as a system for generating, testing, and extending HTTP desynchronization research. The reported live-site tests were conducted on sites covered by an authorized bug bounty program or vulnerability-disclosure policy. The account distinguishes validated impact from speculative leads: generated ideas still need testing, and some remain unproven or hypothetical. Authorization and human validation remain central even when parts of the research process are automated.

Searchlight Cyber’s WordPress analysis

Searchlight’s research account describes autonomous multi-agent analysis that found a chain beginning with pre-authentication SQL injection and leading to remote code execution. Treat the described method and estimated model cost as the company’s account, not as an independent benchmark of how cheaply or reliably AI can find similar flaws elsewhere.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What reported operational outcomes can—and cannot—tell you

Several organizations have published numerical results from their own security operations. These figures help show what teams are measuring, but they have different baselines and come from company case studies or internal tests rather than a shared, controlled evaluation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IBM Concert: vulnerability prioritization

IBM says its CIO and CISO organizations used Concert, built with IBM watsonx products, to prioritize vulnerability risk across hybrid environments. In internal test data from an August 2025 scan, IBM says Concert analyzed 874 applications in 24 hours. Against IBM’s previous CVSS-based approach, it identified 32% more high-priority vulnerabilities, surfaced about 70 lower-severity CVEs for prioritization, reduced its Priority 1 CVE count by 67%, and identified 15% more business applications with elevated vulnerability risk. IBM cautions that the results are illustrative, based on internal data, and that actual outcomes vary; they should not be read as typical customer results.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Cisco: network operations and incident response

Cisco describes an internal architecture combining network segmentation, zero-trust access, hybrid firewalls, telemetry, and developing AgenticOps capabilities. The company says it accelerated software upgrades for 70,000 devices from months to days and improved incident-response time by 50%. These are Cisco-reported case outcomes, not a controlled comparison. Cisco vice president of information security Jack Klecha said: “Attackers are now using AI to weaponize vulnerabilities in a matter of hours, not weeks. Human response times simply aren’t fast enough to keep up manually anymore. The network has to be able to defend itself.” That is an executive’s characterization in the company case study, not a general measured statistic.

Deloitte and Google Cloud: incident response

Deloitte describes helping an unnamed major European government organization respond to a state-sponsored intrusion. Its case study says Google SecOps unified billions of data points, while Gemini let analysts ask questions in natural language and evolve detection rules alongside human expertise. Deloitte’s headline reports threat identification 66% faster. The figure belongs to that case study and its engagement; the reviewed account does not name the customer or establish that the result generalizes to other incident-response teams.

Check Point: platform activity, not prevented attacks

Check Point’s 2024 ESG report says its ThreatCloud AI platform made 3.7 billion security decisions daily. This is a company-reported platform-volume figure, not a count of attacks stopped, vulnerabilities fixed, or incidents prevented.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How AI is being used to test AI systems

Alice, GPT-Red, and Project Glasswing concern the security of AI systems themselves, including jailbreaks, prompt injection, and agent misuse. That is distinct from using AI to detect conventional software vulnerabilities or respond to a network incident. Testing a system with an AI model can help surface risks, but it does not guarantee that the system is secure; findings still need review, validation, and remediation.

How to interpret deployment status and evidence

  • Production use is not the same as broad adoption. The index groups entries it considers in production or having results, but that does not establish how many organizations use them or how consistently they work.
  • A pilot or announcement is not a proven operational outcome. Cloudflare describes Project Glasswing as a pilot; SoftBank announced a service offer for a target sector. Neither description demonstrates universal deployment.
  • Company-reported metrics need their baseline. IBM’s figures compare internal testing with its earlier CVSS-based approach; Cisco’s numbers come from its own case study. They are not directly comparable with each other.
  • Secondary reporting warrants narrower claims. Several 2026 index entries rely on secondary coverage. Where the originating organization’s detailed account is not available here, the finding or deployment should remain attributed to the index and that reporting.
  • Authorized research is different from misuse. Bug-bounty and vulnerability-disclosure testing has permission and rules. Reports of exploit generation by an adversarial group belong in a separate category.

In practice, the clearest question is not whether a security tool “uses AI,” but what task it performs, what evidence supports the claimed result, what human validation remains, and whether the work is authorized. Discovery can produce candidates; defenders still need to confirm impact, prioritize remediation, and verify that a fix closes the issue.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.