
Cybersecurity Scientist: AI Has Crossed into the Live Attack Chain
For many years, security researchers warned that aggressors would use AI to improve existing cybercrime techniques. However according to Examine Point Research’s current “AI Security Report 2026,” the threat landscape has actually entered a new phase: AI is no longer simply assisting assaulters; it is beginning to operate inside real-world attacks.
The report describes a shift from AI as a force multiplier to AI as an active component of cyber operations. It documents invasions in which AI autonomously ran exploitation workflows, creating countless commands across dozens of sessions with very little human instructions.
The modification matters because it lowers the knowledge barrier that typically separated innovative attackers from less-skilled wrongdoers. “AI has crossed into the live attack chain,” the report states.
The researchers found that AI is now appearing throughout several stages of cyberattacks, including social engineering, malware development, vulnerability research, attacker tool creation, and live intrusion assistance. The methods themselves are typically familiar. What has actually altered is the speed and scale at which opponents can perform them.
AI Is Compressing the Cyber Abilities Space
One of the report’s most significant findings is that AI is putting advanced cyber capabilities within reach of a much wider variety of enemies. The scientists stated the assaulters creating the best dangers are not always those with the most advanced tools. Instead, the best hazard originates from groups that can successfully manage AI throughout multiple phases of an attack.
The report mentioned a ransomware-as-a-service group referred to as “The Gentlemen” as an example of how cybercriminals are try out AI. Researchers discovered that the group used AI to assist build its “Glocker” management tool in just 3 days.
The report also noted an important constraint: AI can accelerate opponents, however human understanding still plays a role. One member of the group cautioned others that “you still require to comprehend what you are doing,” revealing that AI enhances opponents’ capabilities however does not get rid of the need for proficiency.
How Attackers Are Accessing AI Capabilities
Inspect Point recognized three primary methods enemies are gaining access to AI abilities. The most typical technique is abusing business AI designs. Opponents are using widely available tools and attempting to bypass safety controls by breaking destructive requests into smaller, less obvious actions.
The report stated aggressors are significantly choosing mainstream AI platforms because they are more capable and available than underground alternatives.
Another growing risk is the theft of AI qualifications. Check Point highlighted the increase of “LLMjacking,” in which lawbreakers use stolen account credentials to gain access to industrial AI services. The report stated one campaign, known as Bissa Scanner, took AI login details from more than 30,000 exposed configuration files.
The 3rd approach includes self-hosted open source models. While these models permit enemies to avoid company security controls and logging, the cybersecurity company stated lots of opponents have discovered them less capable and harder to operate than business AI tools.
AI Produces a New Security Obstacle for Enterprises
The report also highlights an obstacle for companies adopting AI internally. As business release more AI applications, they are creating brand-new prospective attack surface areas.
Examine Point determined threats including AI designs, facilities, and applications, while warning that security practices have not always equaled adoption. The same AI capabilities that assist services automate jobs and improve productivity can likewise present brand-new dangers if they are poorly secured.
For security groups, the challenge is becoming two-sided. They should defend against opponents utilizing AI while also securing the AI systems their own companies rely on.
The Next AI Cybersecurity Fight
The rise of AI-powered attacks indicates a wider shift in cybersecurity. The question is no longer whether assailants will use AI. According to the report, that shift has already taken place.
As Inspect Point concludes in its report, the events observed over the past year represent “a record of what already occurred, setting the stage of what’s anticipated to come.” The next obstacle will be whether defenders can adjust quickly enough as AI becomes more deeply ingrained in cyber operations.
The full report is available here on the Check Point website (registration required).