AI: Cyber Security's New Top Threat
Artificial Intelligence (AI) has not given attackers new capabilities. It has made the ones they already had cheaper, faster, and available to people who could not run them before. Here is what that changes for the utilities, water systems, pipelines and transit agencies we work with.
In November 2025, Anthropic reported disrupting a cyber-espionage campaign, attributed to a nation-state actor, in which an AI model carried out an estimated 80 to 90 percent of the tactical work across roughly 30 target organizations. People still chose the targets and made the key calls.
The United Kingdom's National Cyber Security Centre (NCSC) had already published the finding, in January 2024 and again in May 2025: AI makes the capabilities attackers already had more effective and more efficient and puts them within reach of more people. Check Point’s Annual AI Security Report 2026 put it in one line in July 2026: "AI is now operating attacks, not just enabling them".
The path from research to worldwide usage took about a decade. The timeline below marks key points in the evolution of this technology that continues to reshape our world.
What Attackers Are Doing Now
Social Engineering Without the Tells
The bad grammar that gave phishing away is gone, and the model does background research too. A generative model is now able to write complete pieces in fluent business English, even able to be personalized to suit various writing styles that can be indistinguishable from a human. Open-Source Intelligence (OSINT) automation tools such as SpiderFoot and theHarvester allow for rapid intelligence gathering of entire organizations and their members.
In 2024, staff at the Hong Kong office of the engineering firm Arup transferred funds after a video call in which every participant except the victim was synthetic. Arup confirmed it was targeted with fake voices and images; with the reported loss being about 25.6 million US dollars according to police figures.
The Federal Bureau of Investigation (FBI) issued a public service announcement in May 2025 dealing specifically with voice cloning of senior US officials. Furthermore, Furthermore, Microsoft has documented a Chromium extension in June 2026 that was passing itself off as a legitimate AI assistant, impersonating a real AI vendor with look-alike branding and a typosquatted address. This extension was hijacking browser searches and capturing keystrokes.
Vulnerability Research Advancements
Google's Threat Intelligence Group reported in May 2026 that threat actors are feeding public vulnerability data into AI tools and documented the first zero-day exploit believed to be developed with AI assistance. A zero-day is a flaw with no fix available when it is first used.
Defenders get the same lift from the same technology. Google's Big Sleep agent found its first real-world flaw in widely used software in November 2024, later fixed by developers after they were notified. Recently, Microsoft has announced that for July 2026 patch Tuesday, a record 622 CVEs have been disclosed, Microsoft and analysts have suggested AI tooling is behind the rising volume.
This is certain to bring an increase in security patching volume it is possible that the regular update schedule will no longer be enough.
Criminal Models for Rent
Commercially available models contain guardrails and external safety controls to prevent malicious use according to usage guidelines. However, attackers have found ways to circumvent these controls and use commercial models to write malicious code and create specialized payloads.
New ways through the guardrails keep appearing, some startlingly simple; research published in November 2025 found that rewriting a forbidden request as a poem defeated safety controls across a range of models
Currently, an emergence of malicious LLMs have been available from dark web vendor sites. Palo Alto Networks Unit 42 catalogued the current generation of malicious LLMs in November 2025, including WormGPT 4 and KawaiiGPT. These are wrapped or jailbroken commodity models where researchers could not tell whether these are genuinely retrained models or ordinary ones held jailbroken.
Malware That Asks a Model For Help
Google's Threat Intelligence Group documented the first malware families that call an LLM at runtime in November 2025. One of them, PROMPTSTEAL, was observed in live operations run by a state-sponsored group. The other, PROMPTFLUX, interacts with its Gemini artificial intelligence (AI) model Application Programming Interface (API) to write its own source code for improved obfuscation and evasion. PROMPTFLUX is as of now experimental, Google states it cannot compromise a network or device, and its self-rewriting function was switched off in the sample analyzed. However, it sets a concerning precedent for things to come.
When Your AI Becomes the Target
When deploying AI systems in your organization. These systems can possibly act as attack surfaces through the employment of supply chain style attacks.
An AI assistant that reaches across mail, files, chat and calendars is useful for its reach but is also exposed by it. Text sitting in a document or an email can be written to read as an instruction, and the assistant may follow it. This is known as Prompt Injection; and today it is still mostly researcher work.
Prompt injection vulnerabilities are now being disclosed in AI-enabled applications. A Microsoft 365 Copilot flaw disclosed in June 2025 could extract data with no user action, and Microsoft fixed it and reported no evidence it was ever used.
This pattern reaches past any single vendor. The National Security Agency (NSA) published a cyber security information sheet on Model Context Protocol security in 2026, stating that the layer where AI agents talk to tools is now attack surface.
What This Means for Your Sector
Exploitation Is Outrunning Remediation
The gap between a flaw becoming public and a working attack existing is closing. VulnCheck found that 28.96% of newly exploited CVEs in 2025 were hit on or before the day they were published, and Axios reported on 21 July that research team watched an attacker take just nine hours to create a working exploit for a critical flaw after it was disclosed and then point that exploit at government customers.
The Skill Barrier Is Dropping Fast
CrowdStrike's 2026 Global Threat Report describes AI as lifting less sophisticated actors while amplifying the most advanced, with an 89% year-over-year rise in AI-enabled adversary activity. This will be a prevalent threat as AI models improve their capabilities, and get incorporated into different sectors, amplifying the attack surface.
Your Own Transparency Feeds Their Research
All areas where an AI agent can navigate to are at risk of becoming its reading material. This includes asset inventories, procurement records, standards submissions, interconnection filings, conference talks. Google's May 2026 findings showed actors feeding CVE data and public vulnerability archives straight into AI tools. Any published detail about which controllers and firmware your organization runs allows an attacker to build a profile for faster vulnerability research.
AI at the OT Boundary
Dragos documented a case in May 2026, where an unattributed actor used commercial AI tools during the compromise of a municipal water and drainage utility serving the Monterrey area of Mexico. After reaching the corporate network, the AI found a gateway into the industrial control environment, worked out on its own that it mattered, researched the vendor, built a password list and ran an automated guessing attack. It failed, and no control systems were breached. Current AI models give attackers no new industrial capabilities, and what they change is speed. The attacker had no industrial background. The AI supplied it and found control-adjacent systems within hours.
Then, in late July, on 26 and 27 July 2026, more than thirty Minnesota community water systems were hit in a coordinated attack; in one town the treatment plant controls went down, and the water tower could not be filled for over an hour. Within days the FBI and the Environmental Protection Agency warned that utilities in at least seven states had reported incidents, with effects including loss of pressure and flooding. Attackers reached control devices left exposed on the internet and set passwords on them, locking operators out of their own equipment.
Although there has not been a confirmed OT related attack using AI, it is getting clearer with each attempt that it is only a matter of time.
The Bottom Line
Phishing worked before AI. Weak remote access worked before AI. AI made current capabilities both cheaper per attempt and better per attempt.
Federal guidance is coming but is not here. America's AI Action Plan directed by the Department of Homeland Security (DHS) in July 2025 to establish an AI Information Sharing and Analysis Center, the AI counterpart to the Electricity Information Sharing and Analysis Center (E-ISAC) and Multi-State Information Sharing and Analysis Center (MS-ISAC) channels your teams already use. It has not launched. A Cyber Security and Infrastructure Security Agency (CISA) official described it in February 2026 as still in development.
It is advised to consider the following when dealing with the evolving threat landscape of AI tools.
- Get system control devices off the public internet and put remote access behind a gateway you control.
- Train your organization to familiarize themselves with what attacks look like now. The signs on how to tell previously are no longer valid.
- Shorten the patch window on any internet-facing asset, the time-to-exploit will continue to get smaller.
- Reduce your AI attack surface by limiting what is publicly available from your organization, and put any AI tool you deploy through your existing third-party review
- Create an AI usage policy to better control and govern AI usage in your organization.
Now that we have mapped the threats, we must draft a plan. As your AI Knowledge Center and trusted advisor to critical infrastructure operators, we will walk through how to build an AI strategy that accounts for the risks covered here, from governance and usage policy to reducing the attack surface your own AI creates.
Talk to an AdvisorReferences
- Anthropic. (2025, November 13). Disrupting the first reported AI-orchestrated cyber espionage campaign. Anthropic. https://anthropic.com/news/disrupting-AI-espionage
- Axios. (2026, July 21). AI is shrinking the time to patch software vulnerabilities. Axios. https://www.axios.com/2026/07/21/ai-models-cyberattacks-software-flaws
- Check Point Research. (2026, July). Annual AI Security Report 2026. Check Point, via PR Newswire. https://prnewswire.com/news-releases/check-point-research-ai-has-crossed-from-assistant-to-operator-rewriting-the-rules-of-autonomous-ai-cyber-attack-and-defense-302825086.html
- CNN. (2024, May 16). Arup deepfake scam loss, Hong Kong. CNN. https://cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
- CrowdStrike. (2026, February). CrowdStrike 2026 Global Threat Report. CrowdStrike. https://crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/
- Deen, J. (2026, May 6). AI in the breach: How an adversary leveraged AI to target a water utility's OT. Dragos. https://dragos.com/blog/ai-assisted-ics-attack-water-utility
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2025, May 15). Public service announcement on AI voice cloning of senior US officials. IC3. https://ic3.gov/PSA/2025/PSA250515
- Google Project Zero. (2024, November 1). From Naptime to Big Sleep: Using large language models to catch vulnerabilities in real-world code. Google Project Zero. https://projectzero.google/2024/10/from-naptime-to-big-sleep.html
- Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in threat actor usage of AI tools. Google Cloud. https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools
- Google Threat Intelligence Group. (2026, May 11). AI Threat Tracker update: vulnerability exploitation and initial access. Google Cloud. https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access
- Hackviser. (n.d.). theHarvester. Hackviser. https://hackviser.com/tactics/tools/the-harvester
- Hu, K. (2023, February 1). ChatGPT sets record for fastest-growing user base — analyst note. Reuters. https://www.reuters.com/technology/chatgpt-sets-record-fastest-growing-user-base-analyst-note-2023-02-01/
- IBM Research. (2018, August). DeepLocker: Concealing targeted attacks with AI locksmithing. IBM Research. https://research.ibm.com/publications/deeplocker-concealing-targeted-attacks-with-ai-locksmithing
- Kali Linux. (n.d.). spiderfoot. Kali Linux Tools. https://www.kali.org/tools/spiderfoot/
- Microsoft. (2026, June 29). Chromium extension uses AI-related branding to redirect browser search. Microsoft Security Blog. https://microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/
- OpenAI. (2022, November 30). Introducing ChatGPT. OpenAI. https://openai.com/index/chatgpt/
- Palo Alto Networks. (n.d.). What is a prompt injection attack? Cyberpedia. https://www.paloaltonetworks.ca/cyberpedia/what-is-a-prompt-injection-attack
- Palo Alto Networks Unit 42. (2025, November 25). The dual-use dilemma of AI: Malicious LLMs. Unit 42. https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/
- The Hacker News. (2025, November). Google uncovers PROMPTFLUX malware that uses AI to rewrite itself. The Hacker News. https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html
- The Record. (2026, July). Microsoft smashes Patch Tuesday record for second successive month. Recorded Future News. https://therecord.media/microsoft-vulnerabilities-patch-tuesday-release
- VulnCheck. (2026, January 21). State of Exploitation 2026. VulnCheck. https://vulncheck.com/blog/state-of-exploitation-2026
- Wall Street Journal. (2019, August 30). Fraudsters used AI to mimic CEO's voice in unusual cybercrime case. The Wall Street Journal. https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402