Press TechRound interviews Secure.com CEO on the future of AI security
Read

Hackers Now Run AI as a Daily Work Tool

New research shows hackers use AI to build attacks, break in faster, and slip past safeguards. See what changed and how you can keep pace now

Dateline: August 6, 2026

Two fresh reports out of a major security conference this month say the quiet part loud. Attackers are not just testing AI. They use it every day.

They write malware with it. They manage attack servers with it. They hunt for weak spots with it. And here is the number that should sting: one report clocked an 89 percent jump in attacks by AI-assisted crews over the past year.

This is not a movie plot about smart robots. It is a workflow change, and it already happened.

What Happened?

Two teams of researchers dug into real attacker activity. One pulled apart recovered prompt logs, attacker chatter, and leftover tooling. The other drew on frontline threat-hunting data.

The first team sorted AI abuse into three jobs. Attackers use AI as a coder to build malware. They use it as a force multiplier to run bigger operations. And they use it to speed up the search for software flaws.

The most telling find was how easy it is to get past the safety limits built into these tools. No fancy tricks needed. Attackers just claim they have permission. Something like “this is an authorized test” or “this is a practice exercise” was often enough to get the model to play along. When one tool said no, they moved to a version with no limits at all.

Skill still matters. Beginners built clunky junk that barely ran. Skilled operators built things that surprised even the researchers.

The second report showed AI crushing the time between a flaw going public and attackers using it. In the first half of this year, 88 percent of attacks on flaws with public test code happened within 48 hours of that code dropping. Two state-backed groups moved in under 24 hours.

What’s the Impact?

The window to react is shrinking to almost nothing. If a patch race takes you a week, you already lost. Attackers now move in a day or two.

Trusted logins are a prime target. One report found voice-phishing break-ins doubled in the first half of the year. Fake video and cloned audio are showing up in scam calls aimed at staff. Cloud attacks jumped 171 percent as crews stole credentials and abused AI services.

There is a second front too. The building blocks of AI itself are under attack. One crew slipped bad code into more than 130 packages of a popular AI framework. Poison the supply, and every app downstream drinks it.

The hard truth from the researchers: proof of AI abuse rarely shows up in normal security logs. So a lot of this slips by unseen.

How to Avoid This

You cannot prove AI was involved in every attack, and you should stop trying. Watch for bad behavior instead of chasing the tool behind it.

  • Move to phishing-resistant logins like hardware keys. Push and text codes are getting beaten.
  • Patch on a clock measured in hours, not weeks, for anything with public exploit code.
  • Treat AI tools and their connections as high-value targets. Log them. Lock them down. Vet every outside package before it enters your build.
  • Keep long, off-device logs so attackers cannot wipe their tracks.
  • And match their speed. If they run AI to attack, you need AI to sort the flood of alerts your team cannot clear by hand.