When AI Becomes Both Weapon and Target
We're witnessing a fundamental shift in cyber risk. For the first time in our reporting, the majority of today's critical threats involve AI systems—not as victims of attacks, but as the attack surface itself. BioShocking prompt injections trick autonomous agents into stealing credentials. Poisoned tool descriptions manipulate agents into leaking data. Shell injection vulnerabilities in AI coding agents let attackers execute arbitrary commands with full developer permissions. And a new attack called agentjacking uses fake bug reports to compromise coding agents at scale. Simultaneously, exposed AI endpoints are being weaponized as free compute for offensive operations, and 282 iOS AI apps are leaking API credentials through plaintext backends. This isn't isolated risk—it's systemic fragility in the tools we're building to defend ourselves.
The deeper problem is architectural. Traditional security assumes humans make final decisions. AI agents don't. They optimize toward completion of their objectives, which makes them vulnerable to reframing attacks: phantom squatting exploits AI hallucinations by registering domains that language models invent during conversations, then hosting phishing sites on them. AI-generated workflows function perfectly while embedding invisible security flaws—overprivileged access, credential exposure, unvalidated data—undetectable by teams who assume correct output means secure process. These aren't bugs in individual implementations. They're design vulnerabilities in how we're deploying autonomous systems without sufficient guardrails.
Yet critical infrastructure remains under coordinated state-sponsored assault that makes these AI vulnerabilities look like opening moves. A Chinese APT escalated from Taiwan to Southeast Asia, compromising 10+ critical-infrastructure organizations—state-owned power and water utilities—using a new TinyRCT backdoor. This represents a significant shift in Chinese operations toward essential services. Meanwhile, USB drives carrying China-linked malware infiltrated Japan's military in March 2024, remaining undetected for 11 months—a gap that exposes critical weaknesses in military network security protocols. The supply chain remains compromised: malicious PyPI packages with 25,000+ downloads gave attackers complete control of Telegram bot servers, while a seemingly minor Oracle PeopleSoft vulnerability (CVE-2026-35273) breached Nissan and 100+ other organizations, exposing employee SSNs and banking data. What these incidents share is dwell time—attackers maintained access for months before detection. Visibility has become the industry's most critical deficit.
The patch velocity has become mathematically unsustainable. Google's Chrome 151 patches 382 vulnerabilities, including 15 critical flaws discovered via AI security scanning. Apple released emergency patches for 30+ vulnerabilities, with four critical WebKit flaws enabling remote code execution. Adobe patched seven maximum-severity ColdFusion and Campaign flaws. Citrix patched six NetScaler vulnerabilities. Progress Kemp LoadMaster carries a pre-auth RCE flaw (CVSS 9.8) with public exploits available. SimpleHelp's OIDC bypass is actively exploited to deploy Djinn Stealer malware. This isn't a backlog problem anymore—it's a triage problem. Organizations must choose which critical vulnerabilities not to patch.
The industry's response has been to commoditize LLM capabilities and secure investment in specialized defense. Anthropic restored Claude Fable 5 after the U.S. lifted export controls imposed just 16 days earlier, highlighting how quickly geopolitical shifts can disrupt AI innovation. Anthropic rolled out Sonnet 5 with near-Opus performance at lower cost, democratizing enterprise-grade AI for teams. Simultaneously, security startups raised record capital: Dawnguard raised $6.3M for security architecture automation, and Quantifind closed $200M for AI-native financial crime prevention. These aren't confidence plays—they're necessity. The attack surface has expanded faster than traditional security can defend.
Identity security has emerged as both the highest-leverage attack vector and the most accessible entry point to the profession. An 81-million-attempt password spray campaign against Azure CLI compromised 78 Microsoft accounts across 64 organizations, bypassing MFA through deprecated OAuth—a stark reminder that MFA is often compliance theater rather than complete security. Yet identity security remains the entry point for 70% of breaches, creating paradoxically high demand for identity specialists in an industry struggling to recruit. The Supreme Court's recent 6-3 ruling that cellphone location data receives Fourth Amendment protection signals that digital privacy is becoming constitutionally protected, which will reshape both law enforcement practices and defensive security requirements.
Long-term threats are accelerating in parallel. Microsoft set a 2029 deadline for quantum-safe encryption on critical systems, responding to "harvest now, decrypt later" attacks where adversaries collect encrypted data today for future decryption when quantum computers mature—a threat that's no longer theoretical but actively being executed by state-sponsored and criminal groups. ClickFix malware evolved into a sophisticated API-driven platform serving customized payloads in 25 languages while bypassing Windows AMSI, creating a commercialized threat ecosystem. Fraud infrastructure is being industrialized: attackers registered 212 fraudulent domains impersonating Venezuela earthquake relief in just 5 days, and pre-deployed infrastructure targets FIFA 2026 fans across multiple sectors and languages.
The convergence of these trends—AI vulnerabilities, infrastructure targeting, patch saturation, identity as the linchpin, and long-term quantum threats—defines the security agenda for the next 18 months. Organizations that treat AI security as an afterthought will face compounding risk. Those that treat identity as purely a compliance exercise rather than foundational defense will be compromised. And those without quantum-safe migration plans will face decryption of historical data within a five-year window. The patch treadmill isn't slowing. Neither are the attackers.
Key Takeaways
- AI security is now foundational infrastructure risk. Poisoned tool descriptions, prompt injection, shell injection in AI agents, and agentjacking represent new vulnerability classes that bypass traditional endpoint defenses. Teams deploying autonomous systems must assume adversarial input and isolate agent permissions.
- Identity and authentication remain the highest-leverage attack surface. The Azure CLI spray campaign's success despite MFA indicates that organizations are treating multi-factor authentication as compliance theater rather than security. Deprecated authentication protocols and OAuth weaknesses are still being actively exploited.
- Patch velocity has exceeded human capacity. With 382 Chrome vulnerabilities, 30+ Apple flaws, and seven critical Adobe patches released simultaneously, organizations cannot patch everything. Shift focus to threat modeling based on asset criticality and dwell time detection rather than comprehensive patch coverage.
- Quantum-safe migration must begin now. State-sponsored actors are actively executing "harvest now, decrypt later" strategies against encrypted data today. Microsoft's 2029 deadline for critical systems is aggressive but achievable only if planning begins immediately on legacy infrastructure.
The Wire is HackWire's daily editorial briefing, published every morning.