Speed Has Won. The Security Industry Has Lost.
For two decades, the industry has built its defensive strategy on a simple premise: detect quickly, respond faster, patch before exploitation. That model is dead. Today's brief crystallizes why: we are watching security's operating assumptions collapse in real time, outpaced by adversaries who have weaponized AI to compress entire attack cycles into hours.
The evidence is everywhere. AI-Driven Vulnerability Surge Breaks the Traditional Patching Model reports that high and critical vulnerabilities have doubled year-over-year, driven by AI-accelerated exploitation. More damning: Phishing 3.0: The Fight Moves to Agent Versus Agent reveals that human attackers have been replaced by automated agents orchestrating thousands of simultaneous campaigns. And in the APAC theater, China-Linked Hacker Shows AI Capabilities in APAC Attack documents nation-state actors deploying AI operationally—not experimentally—for reconnaissance and mass personalized social engineering. The shift from human-versus-human to machine-versus-machine isn't coming. It's here.
The cost of this speed advantage is precision targeting and supply chain destruction. Critical GitLab Flaw Exploited Shortly After Disclosure describes a GraphQL injection (CVE-2026-19478) that was weaponized within 48 hours of disclosure, enabling attackers to forge commits and delete projects. GitLab is the source-of-truth for thousands of development pipelines—a single exploited instance means an attacker can impersonate trusted maintainers and inject backdoors into dependencies downloaded by millions. Similarly, Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code documents an unauthenticated file-upload RCE affecting any published form, and StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data shows attackers have already weaponized 2,000 compromised WordPress installations to distribute malware while bypassing reputation-based filters. The infrastructure layer is contaminated.
But supply chain vulnerabilities are only half the story. Vendor breaches now trigger cascading failures across entire industries. Healthtech firm CareCloud data breach impacts 3.7 million patients initially reported 350,000 affected individuals—until the true scope emerged: 3.7 million. This is the aggregator problem in its starkest form: one vendor serving thousands of practices creates a single point of failure that multiplies across the entire ecosystem. Patients discover the breach slowly as covered entities audit the full scope weeks later. The same pattern emerges in Sakura Internet hack exposes data of up to 1.36 million accounts, where a single breach of a hosting provider's sales system creates a targeting manifest of thousands of Japanese businesses relying on their infrastructure—followed by secondary attacks against downstream customers. One vendor down. Thousands of businesses compromised. The security perimeter no longer exists.
Physical infrastructure is now under AI-powered siege. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure marks a threshold: AI isn't just accelerating digital exploitation anymore—it's targeting the devices that burst pipes, overdose chemical systems, and black out cities. And CISA: Medusa ransomware hit over 500 critical infrastructure orgs reveals the scale: Medusa ransomware-as-a-service has compromised over 500 critical infrastructure targets since 2021, each hit with extortion demands up to $15 million. Meanwhile, Hackers compromise 14,500 Dahua web cameras in 35-day campaign documents adversaries methodically compromising 14,500 surveillance cameras over 35 days—unpatched vulnerabilities in devices common to warehouses, parking garages, and infrastructure control rooms. Reconnaissance at industrial scale. The cameras that were supposed to watch for threats are now part of the threat.
Even when patches exist, they fail catastrophically. Microsoft fixes known issue causing Windows Defender crashes details a bug that disabled real-time protection, EDR functionality, and security logging—creating dangerous blind spots where threats slip through undetected. When Defender fails, organizations lose not just AV scanning but compliance visibility and telemetry pipelines. The safety net evaporates. And Windows 11 24H2 Home and Pro reach end of support in 2 months creates a permanent vulnerability window: most consumer users don't realize their machines will stop receiving security updates in October, while enterprise editions get 36 months of support. A stark security divide guaranteed by economics, not capability.
The authentication layer, once considered a fundamental defense, is now Swiss cheese. Password spraying attacks surge 155x as hackers exploit MFA gaps exposes the blindspot that most defenders missed: 81 million login attempts in two weeks succeeded because legacy auth protocols (IMAP, SMTP, CalDAV) bypass MFA entirely. Attackers spray passwords against thousands of accounts undetected. MFA defended the front door while the side door swung open.
Even the platforms we've built to be secure are now becoming attack vectors. OpenAI confirms ChatGPT is down as logins and signups fail shows that ChatGPT's authentication collapse revealed how operationally critical the service has become for enterprises—yet it lacks fallback systems for critical workflows. And CoSnitch Attack Tricked Copilot into Mapping Out Architecture demonstrates that AI assistants themselves can be tricked into revealing their own security flaws and architecture, giving attackers exploitation roadmaps for the tools enterprises are betting their security on. Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second reveals that shared infrastructure—even Cloudflare's—can leak authentication tokens via side-channel attacks at 360x faster than previous exploits. A full JWT can be stolen in 6-9 minutes.
The evidence is overwhelming: detection-first security, which improved dwell times to 10-16 days, is now useless. AI-powered attacks complete in hours. Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks names the problem explicitly: prevention, not detection, must be the priority. But prevention requires defending what you don't know is exposed (supply chains), protecting infrastructure you don't control (vendors), and patching faster than vulnerabilities emerge—a problem with no solution under the current model.
The industry is operating under instructions from a world that no longer exists. Speed has won. What comes next requires fundamentally different thinking about resilience, isolation, and the acceptance that breach is inevitable. We'll explore that shift in tomorrow's brief.
Key Takeaways
- Speed has compressed the attack cycle to hours. AI-accelerated exploitation now outpaces traditional detection and patching workflows. Prevention—not detection—must become the primary defensive strategy.
- Vendor breaches now cascade across entire industries. A single compromised vendor serving thousands of practices (CareCloud: 3.7M affected) or infrastructure providers (Sakura, Dahua) means one breach becomes thousands. Vendor risk is now existential risk.
- Legacy protocols and auth gaps undermine MFA. 155x surge in password spraying attacks exploits IMAP, SMTP, and CalDAV protocols that bypass MFA entirely. Modern security architectures must eliminate legacy authentication pathways.
- Physical infrastructure is now AI-targeted. PLCs, surveillance cameras, and critical systems are under systematic attack. Dahua's 14,500-camera compromise and AI-powered attacks on Siemens PLCs signal that the digital-physical boundary has collapsed.
The Wire is HackWire's daily editorial briefing, published every morning.