CrowdStrike's data shows attacks by AI-enabled adversaries rose 89% in 2025, with over 90 organizations observed having their legitimate AI tools exploited to generate malicious commands and steal sensitive data . The average eCrime breakout time — the window between initial access and lateral movement — dropped to 29 minutes, with the fastest recorded breakout at just 27 seconds
. This represents a 65% speed increase from 2024
.
Key trends driving this include:
The CrowdStrike report identified that DPRK-nexus adversaries (North Korea-linked groups) poisoned 131 trusted AI framework packages, including injecting malicious packages into Mastra AI frameworks . This demonstrates how AI development pipelines themselves have become high-value targets for state-backed groups.
Dataminr's 2026 Mid-Year Cyber Threat Landscape Report highlights a severe asymmetry between defense and offense :
The picture is stark: attackers move in minutes; defenders still need weeks or months to patch.
Cisco Talos published research at Black Hat showing that commercial AI safety controls are alarmingly easy to bypass :
The conference saw the industry moving beyond "adding copilots" to embedding AI into operational security workflows :
The consensus across every major report at Black Hat 2026 is that AI is simultaneously a massive accelerant for attackers and an indispensable tool for defenders :
As one report summarized: "AI is on track to become part of the security team, part of the attack surface, and part of the problem all at once" . The fundamental challenge of 2026 is that attackers have already operationalized AI for speed and scale, while defenders are still racing to catch up against an adversary that now breaks out in minutes and exploits vulnerabilities in hours.