For decades, cybersecurity has been a human-speed arms race: attackers find vulnerabilities, defenders patch them, attackers find new ones. In 2026, that dynamic has changed. AI-powered attack tools are now operating at machine speed — finding, exploiting, and pivoting through networks faster than human security teams can respond. The implications for every organisation that depends on digital infrastructure are severe.
The New Attack Landscape
Security researchers at CrowdStrike and Mandiant have documented a new class of attacks they call "adaptive persistent threats" — malware that uses on-device AI to modify its own behaviour in response to defensive measures. When it detects an EDR (endpoint detection and response) tool, it changes its signature. When it encounters a honeypot, it backs off and tries a different vector. When it identifies a patched vulnerability, it automatically searches for adjacent unpatched systems.
CrowdStrike's 2026 Global Threat Report, published in February, documented a 340% increase in AI-assisted intrusion attempts over the previous 12 months. The report identified 23 distinct threat actors using AI-augmented tools, including nation-state groups from Russia, China, North Korea, and Iran, as well as several sophisticated criminal organisations operating as ransomware-as-a-service providers.
Phishing at Scale
AI has also transformed phishing. The new generation of spear-phishing attacks uses large language models to generate highly personalised emails based on scraped social media data, writing in the target's own communication style and referencing real recent events in their life. Detection rates for these attacks are 60% lower than for traditional phishing, according to research published by Proofpoint in March 2026.
Voice cloning has made phone-based attacks — vishing — significantly more dangerous. Attackers can now clone a CEO's voice from as little as 30 seconds of publicly available audio, then call the CFO requesting an urgent wire transfer. Several Australian companies have reported losses exceeding $2 million from this attack vector in the past six months, according to the Australian Cyber Security Centre's most recent advisory.
Automated Vulnerability Discovery
Perhaps the most alarming development is AI-assisted vulnerability discovery. Security researchers have demonstrated that LLMs fine-tuned on vulnerability databases can identify novel zero-day vulnerabilities in open-source code at a rate that far exceeds human researchers. The same capability is available to attackers. Google Project Zero's 2026 annual report noted a 180% increase in zero-day vulnerabilities discovered in the wild — a figure that researchers attribute in part to AI-assisted discovery by threat actors.
The Defensive Response
The security industry is responding with AI of its own. Microsoft's Security Copilot 3.0 can analyse and respond to security incidents in seconds rather than hours, correlating signals across endpoints, email, identity, and cloud infrastructure simultaneously. CrowdStrike's Charlotte AI can autonomously contain a detected intrusion — isolating affected systems, revoking compromised credentials, and blocking lateral movement — before a human analyst has even been paged.
But the fundamental asymmetry remains: attackers need to succeed once; defenders need to succeed every time. AI amplifies this asymmetry. An attacker with AI tools can probe thousands of targets simultaneously; a defender with AI tools can respond faster, but is still reacting to attacks that have already begun.
What Organisations Should Do
Security experts recommend a shift from perimeter-based to identity-based security models, aggressive adoption of zero-trust architectures, and investment in AI-powered security operations centres. Specific priorities include: implementing phishing-resistant multi-factor authentication (passkeys or hardware security keys) across all accounts; deploying EDR on every endpoint; and establishing a formal incident response plan that has been tested in tabletop exercises.
For smaller organisations without dedicated security teams, managed detection and response (MDR) services from providers including CrowdStrike, SentinelOne, and Microsoft offer enterprise-grade AI-powered monitoring at accessible price points. The Australian Signals Directorate's Essential Eight framework provides a practical baseline for organisations of all sizes.
The Insurance Dimension
Cyber insurance premiums have risen 40% in 2026 as AI-powered attacks increase the frequency and severity of successful breaches. Insurers are now requiring evidence of specific security controls — including phishing-resistant MFA, EDR deployment, and tested incident response plans — before issuing policies. For many organisations, the insurance requirement is becoming the forcing function for security investment that internal risk assessments failed to provide. If your organisation hasn't reviewed its cyber insurance policy and the controls it requires, now is the time.
Sources & Further Reading
- CrowdStrike — 2026 Global Threat Report: AI-assisted attack trends and threat actor profiles
- Mandiant — M-Trends annual threat intelligence report
- Australian Signals Directorate — Essential Eight cybersecurity framework
- Google Project Zero — zero-day vulnerability research and annual statistics
- Proofpoint — State of the Phish annual report on phishing trends and detection rates