AI is accelerating attacks, skilled human operators are already moving at machine speed, and prevention increasingly has to happen before malicious content is ever allowed to run.
For years, cybersecurity strategy has rested on a familiar sequence. An attacker gets in, security tools flag suspicious behavior, analysts investigate, and responders contain the damage. It’s a model built on one quiet assumption: that defenders have time to work with.
That assumption is starting to look dangerously out of date. Artificial intelligence is helping attackers research vulnerabilities, write convincing lures, generate and patch code, automate reconnaissance, and string together multiple stages of an intrusion. Meanwhile, experienced human operators are proving they don’t even need the AI to move that fast. Prepared tooling and disciplined tradecraft get them there on their own.
So the defining cybersecurity problem of 2026 isn’t really that attackers are using AI. It’s that the gap between exposure, exploitation, lateral movement, and data theft is shrinking toward zero, and it’s shrinking whether or not a model is involved. When a compromise can go from an exposed application to cloud credentials and an internal bastion host in a matter of seconds, detection is still necessary, but detection that only kicks in after execution may no longer be enough on its own.
The eight-second warning
In September 2026, the Sysdig Threat Research Team documented an intrusion built around CVE-2026-39987, a critical, pre-authentication remote-code-execution flaw in the open-source Marimo Python notebook platform.
The bug existed because Marimo’s terminal WebSocket endpoint skipped the authentication check applied everywhere else in the app. An unauthenticated attacker could open a single WebSocket connection and land an interactive shell. Versions through 0.20.4 were affected, and the issue was fixed in 0.23.0, according to the project’s GitHub security advisory.
During the intrusion Sysdig observed, the attacker entered the vulnerable environment, pulled stored AWS credentials, retrieved a private SSH key out of AWS Secrets Manager, and authenticated into an internet-facing bastion host. Once the operator’s custom toolkit was ready, the entire pivot, from a fresh WebSocket connection all the way to SSH access on the bastion, took eight seconds.
What makes the case worth sitting with is that Sysdig found no evidence of an AI agent or a public offensive framework anywhere in it. The attacker wrote and debugged the Python tooling by hand over the preceding hours, then used the finished automation to run the credential-pivot chain at machine speed. This wasn’t an autonomous AI attack. It was a capable person who had done the prep work.
Sysdig had actually seen the same Marimo vulnerability exploited by AI before this. In that earlier incident, an LLM-directed operation moved through four separate pivots and pulled the schema and full contents of an internal PostgreSQL database in under two minutes. Set the two cases side by side and the takeaway is uncomfortable: defenders can’t count on being able to tell whether an attacker is human, scripted, or AI-directed, because the operational result can end up looking almost identical either way.
The real lesson from the Sysdig investigation is that the threat is no longer defined by who, or what, is typing the commands. It’s defined by how fast a successful entry point can be turned into control of everything downstream.
AI is changing the economics of cybercrime, not just the tooling
AI doesn’t need to invent some revolutionary new malware family to reshape cybercrime. Its biggest near-term impact might just be economic.
Work that used to require several specialists can now be pulled together by one operator with a generative model at hand: vulnerability research, exploit adaptation, infrastructure scripting, translation, target profiling, phishing content, malware modification, troubleshooting. All of it, faster, with fewer people.
Anthropic’s September 2026 threat-intelligence report described disrupted activity involving state-aligned operators, financially motivated criminals, surveillance vendors, and influence operations, drawn from activity observed between December 2025 and August 2026. Its central conclusion was blunt: sophisticated operations no longer require equally sophisticated attackers, because AI strips away much of the labor, knowledge, and tooling that used to gate them. You can read more in Anthropic’s report and the Associated Press summary.
The broader industry data points the same direction. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87 percent of respondents saw AI-related vulnerabilities as the fastest-growing cyber risk of 2025. CrowdStrike reported an 89 percent jump in AI-enabled adversary activity and put the average eCrime breakout time at just 29 minutes in its 2026 Global Threat Report.
None of this means every attack today is autonomous. It means AI is becoming a force multiplier across the whole threat ecosystem, even as ordinary automation and skilled human operators keep producing machine-speed results entirely on their own.
The same pattern, showing up everywhere
The shrinking response window isn’t confined to one type of attack. It shows up across several threat categories that, on the surface, don’t have much in common.
Exploitation has become the front door
Mandiant’s M-Trends 2026 found that exploitation was the most frequently observed initial infection vector for the sixth year running, accounting for 32 percent of intrusions where the entry method could be identified. The 2026 Verizon Data Breach Investigations Report tells a similar story, with exploitation of software vulnerabilities now the leading initial-access vector at 31 percent of breaches, the first time it has overtaken credential abuse in the report’s 19-year history.
That matters because exploitation scales in a way persuasion never quite does. An attacker doesn’t need to talk each target into anything individually. Once a working exploit exists, exposed systems can be found, tested, and compromised at scale, automatically.
The Marimo case is an extreme version of this. Sysdig observed exploitation of CVE-2026-39987 less than ten hours after it was disclosed. Once access was established and the tooling was ready, the attacker could repeat the critical post-exploitation steps in seconds, over and over.
The patch gap is becoming a weapon in its own right
Proofpoint’s September research into the BlueMoon exploit kit showed how fast a capability can spread once it exists. The company tracked four separate espionage-focused actors, TA412, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, using the same exploit kit within roughly a week of each other.
BlueMoon chained two Chromium V8 vulnerabilities with a Windows privilege-escalation flaw, enough to achieve code execution, escape the sandbox, and gain elevated access. The actors went after NGOs, aerospace interests, energy-related entities, manufacturers, and organizations across Southeast Asia. Instead of staying locked to one highly capable group, the exploit chain was operationalized by several actors in the narrow window between the vendor’s patch and its widespread deployment. Proofpoint’s BlueMoon analysis has the full campaign detail.
Google separately confirmed that an exploit for CVE-2026-85046, a V8 type-confusion bug, was already circulating in the wild when it shipped its September Chrome security update. In today’s patch gap, disclosure doesn’t just inform defenders. It can hand attackers a roadmap for reverse-engineering the fix, building an exploit, and scanning for anyone who hasn’t updated yet.
Vulnerability discovery is outrunning remediation
Microsoft’s September 2026 Patch Tuesday gives a sense of scale. Microsoft addressed a record 974 vulnerabilities across Windows, Office, SQL Server, developer tools, and more. Over 110 were rated Critical, and two of the Windows flaws were already being exploited before the patch shipped.
That volume doesn’t mean every vulnerability carries the same risk. But it does expose a widening gap: automated and AI-assisted discovery can now produce vulnerabilities faster than most enterprises can test and roll out patches for them. Full details are in the Microsoft Security Update Guide, with prioritization analysis from CrowdStrike and Dark Reading. Treating all 974 findings as equally urgent isn’t realistic. Organizations have to prioritize by active exploitation, internet exposure, business context, reachable attack paths, and whatever compensating controls are already in place.
Even a security gateway can become the target
On September 14, Cisco disclosed active exploitation of CVE-2026-76461, a critical vulnerability in physical and virtual Cisco Secure Email Gateway appliances. According to Cisco’s advisory, weak validation in the email-parsing logic let an unauthenticated attacker send a crafted email containing malicious SQL statements, and successful exploitation could hand over arbitrary command execution with root privileges on the underlying OS. No workaround exists, so customers have to install the fixed software. Cisco also warned that an attacker with root access might scrub local evidence, which makes external network and firewall logs important for anyone investigating.
The case points to a broader architectural problem: a security product often has to parse untrusted content before it can even decide whether that content is safe. If the parser itself is vulnerable, the inspection process becomes the exploit path. That’s why parser isolation, strict input validation, least privilege, a diversity of inspection controls, and fast patching all matter so much. A content-security layer sitting behind a vulnerable gateway can’t retroactively undo an exploit that already happened inside the gateway’s own parser.
Social engineering is getting more interactive and more personal
Technical exploitation is only half the acceleration story. Attackers are also getting faster and more convincing on the social engineering side.
Mandiant reported that voice phishing rose to 11 percent of observed initial infection vectors, making it the second most common method in its 2026 findings. That’s a real shift away from static phishing emails and toward interactive operations, where a caller impersonates an employee, an IT technician, a vendor, or a trusted contact and walks the victim through authentication or remote-access steps in real time.
AI makes these operations easier to scale: fast target research, multilingual scripts, personalized pretexts, synthetic voices, convincing documents, responses that adapt on the fly. A target might see what looks like a legitimate message, then get a believable phone call, then a familiar-looking login page, then instructions tailored to how their organization actually works. Any single signal in that chain can look harmless on its own. The danger only becomes visible once you look at the whole sequence together.
State spyware still starts with trust and a file
A joint warning issued by the United Kingdom, the United States, and the Netherlands on September 15 described Iranian state-linked operations targeting dissidents, journalists, activists, and other perceived opponents. The UK’s National Cyber Security Centre named the malware family CHOSEN BRICK, and the FBI’s technical advisory analyzes related activity under the HEAVYGRAM designation.
The actors approached victims through Telegram, WhatsApp, Instagram, and other channels, sometimes posing as trusted contacts or offering IT services. Victims were talked into installing remote-access software or downloading malware disguised as ordinary applications. The FBI examined samples masquerading as an AI video generator and a Telegram authentication app. Once running, the components could establish persistence, weaken Microsoft Defender, steal browser credentials, pull Telegram and WhatsApp data, extract Outlook messages and attachments, capture screenshots, access microphones, and take further commands. Nothing about it relied on some exotic zero-click technique. It ran on identity, trust, convincing communication, and files that looked like they served a legitimate purpose. The full picture is in the FBI’s technical advisory, the UK NCSC warning, and Reuters’ report.
Familiar document attacks haven’t gone anywhere
FortiGuard Labs recently analyzed a Casbaneiro banking-trojan campaign aimed at Latin American users through phishing emails and PDFs disguised as invoices or legal notices. The PDF kicked off a multistage delivery process that used geofencing and other tricks to keep researchers and automated analysis tools from ever seeing the payload real victims got. The HTA downloader and the malware itself carried their own environmental and geographic checks on top of that.
The FortiGuard Labs analysis is a good reminder that attackers don’t need a new delivery concept when they can just keep sharpening an old one. The document builds credibility. The link or embedded action starts the chain. Conditional delivery hides the payload from scanners. The malware that finally lands steals information that feeds more fraud down the line.
Software supply chains amplify every successful compromise
Attackers are increasingly going after the files and packages developers already trust by default. Socket’s investigation into SANDWORM_MODE described an npm worm that compromised repositories, stole CI/CD secrets, modified workflows, and tried to poison developer AI toolchains by way of malicious MCP servers aimed at tools like Claude Code, Claude Desktop, Cursor, VS Code’s Continue, and Windsurf. Instead of compromising a single workstation, a malicious package or build process can spread through downstream projects and automated deployment pipelines. Socket’s technical report lays out the full campaign.
Recent exploitation of GitLab’s CVE-2026-85706 makes the same point from a different angle. CISA added it to its Known Exploited Vulnerabilities catalog on September 11, underscoring that development infrastructure has become a high-value route straight to source code, credentials, build systems, and downstream customers. In an AI-assisted development environment, the fallout can spread even further. Agents can automatically pull packages, process repositories, follow embedded instructions, and pass compromised content into whatever comes next. A poisoned dependency isn’t just a developer’s problem anymore. It can become an automated distribution mechanism.
The common thread is trusted content
These incidents span very different technologies and very different adversaries, but most of them share a pattern: something treated as legitimate gets permitted to cross a trust boundary. It might be a Python notebook exposed for collaboration, a browser rendering an attacker-controlled page, an email gateway parsing a crafted message, a PDF dressed up as an invoice, a fake installer sent over Telegram, or a package pulled from a registry everyone assumes is safe.
Traditional security tends to ask whether a file, URL, user, process, or behavior is already known to be malicious. Machine-speed attacks expose the weakness in that question directly. By the time enough malicious behavior has piled up to support a confident verdict, the attacker may already be holding credentials, tokens, cloud secrets, or a foothold in another system entirely.
A prevention-oriented architecture asks an earlier question instead: what is this content actually capable of doing, and should it be allowed to do that here? That’s the difference that makes a Content Security Layer worth building.
Where FileDNA fits
FileDNA’s Content Analysis, Disarm and Reconstruction approach is built to examine supported files before their active content ever reaches a user, an application, an AI workflow, or a downstream security product. Rather than leaning on malware signatures alone or waiting for something to execute, FileDNA identifies the actual file format, recursively inspects embedded content, decodes supported scripts and objects, surfaces structural inconsistencies, evaluates what a file’s active capabilities actually are, and reconstructs a safer version according to policy.
Take that invoice-themed PDF campaign as an example. A Content Security Layer could inspect the document’s structure, identify embedded or linked active behavior, pull out nested objects, and apply policy before the document ever reaches the recipient. For Office files, scripts, archives, and other supported compound formats, deep unpacking can reveal macros, JavaScript, PowerShell, VBScript, embedded executables, misleading extensions, and nested content that would otherwise stay hidden inside a container that looks perfectly trustworthy.
This matters even more for AI systems. An ingestion pipeline might process thousands or millions of externally supplied files without a person ever reviewing one of them individually. Malicious instructions, scripts, malformed objects, and hidden payloads can move straight from an upload into automated parsing, indexing, retrieval, or agent workflows unless something validates the content first, before it gets trusted as data. FileDNA is meant to be that upstream enforcement point: receive, recognize, unpack, analyze, apply policy, reconstruct, validate, deliver. It doesn’t replace EDR, XDR, SIEM, identity protection, vulnerability management, or runtime monitoring. It reduces how many dangerous files and active capabilities those downstream systems ever have to deal with in the first place.
Where a Content Security Layer doesn’t break the chain
It’s worth being precise about scope here. FileDNA wouldn’t have patched the Marimo WebSocket vulnerability, wouldn’t have prevented direct network exploitation of an exposed service, and wouldn’t stop an attacker who already holds valid cloud credentials. Those problems call for patching, exposure management, network controls, secret isolation, least privilege, and behavioral detection, not content inspection.
It wouldn’t, on its own, stop a voice-phishing victim from approving an authentication request or reading off a one-time code. That calls for identity verification, phishing-resistant authentication, conditional access, and solid help-desk procedures. It wouldn’t stand in for Cisco’s fix to CVE-2026-76461 either. If the vulnerable Cisco gateway parses an attacker’s message before FileDNA ever sees it, exploitation can happen first. Real protection there means patching the gateway or putting an independent inspection layer ahead of the vulnerable parser.
And FileDNA shouldn’t be pitched as a universal executable-control product. When someone deliberately downloads and runs a standalone malicious installer, application control, endpoint prevention, reputation services, and EDR are still what matters most. FileDNA does its best work at the content boundaries where documents, archives, scripts, embedded objects, and reconstructable files pass through, not at the point where someone chooses to run something on purpose.
The honest security model is a complementary one. FileDNA reduces risk before supported content ever executes. Vulnerability management closes off exploitable software paths. Identity controls constrain what stolen credentials and social engineering can actually accomplish. EDR and runtime security catch behavior that slips past upstream controls. SIEM, XDR, and MDR correlate activity across all of it and coordinate the response.
Defending when seconds matter
The answer to machine-speed attacks isn’t just asking analysts to work faster. Human investigation can’t reliably keep pace with an intrusion that pivots in eight seconds. Organizations need controls that make decisions and enforce boundaries before an attacker’s sequence has a chance to unfold.
First, exposed services need continuous inventory and prioritization based on evidence of active exploitation, not just severity scores. CISA’s Known Exploited Vulnerabilities catalog, vendor advisories, internet exposure, privilege context, and reachable assets should all be driving emergency remediation decisions.
Second, credentials can’t be treated like ordinary application data. Workloads should get only the permissions they actually need, long-lived secrets should be eliminated wherever possible, and a compromised application should never be a straight line to your high-value keys or internal bastions.
Third, untrusted content needs to be validated before it reaches vulnerable or privileged parsers, and that includes email attachments, uploads, cloud storage, collaboration tools, developer packages, data-ingestion pipelines, and AI knowledge systems alike.
Fourth, organizations should be watching for attack chains, not isolated events. An unusual WebSocket connection, a Secrets Manager request, and an SSH login can each look explainable on their own. Strung together within a few seconds, they describe a credential-pivot sequence in progress.
Finally, prevention and detection have to work as layers that reinforce each other. Prevention cuts down on how many dangerous actions ever get to begin. Detection catches whatever slips past those preventive controls. Response contains what’s left.
The new security question
The question worth asking is no longer how quickly a team can respond after a compromise. It’s how many attack stages can be stopped from ever starting.
The Marimo intrusion compressed a cloud pivot into eight seconds. BlueMoon showed four separate espionage actors adopting the same exploit chain within days of each other. Microsoft’s record patch release showed just how large the remediation problem has gotten. Cisco’s email-gateway vulnerability showed that even security infrastructure can be compromised by the very content it’s supposed to inspect. Casbaneiro, CHOSEN BRICK, and the software-supply-chain campaigns all showed that trusted-looking files and packages are still remarkably effective delivery vehicles.
AI will keep accelerating all of this, but waiting around to identify an “AI attack” misses the bigger shift. Human operators, scripts, criminal services, exploit kits, and autonomous agents are all converging on the same operational advantage: speed. When the response window collapses, the decisions made upstream, about what to trust, start to matter more than almost anything else. Files need to be understood before they’re opened. Embedded capabilities need to be exposed before they execute. Dangerous content needs to be removed or rejected before it ever enters a trusted workflow.
Detection still matters, and it isn’t going away. But in an eight-second attack chain, the strongest response might just be the stage that never gets permission to start.
References
- Sysdig — Machine Speed, Hold the AI: Hand-Rolled Marimo CVE-2026-39987 Exploit
- Sysdig — AI Agent at the Wheel: From a CVE to an Internal Database in Four Pivots
- Marimo GitHub Security Advisory — CVE-2026-39987
- World Economic Forum — Global Cybersecurity Outlook 2026
- CrowdStrike — 2026 Global Threat Report
- Google Cloud/Mandiant — M-Trends 2026
- Verizon — 2026 Data Breach Investigations Report
- Microsoft — September 2026 Security Update Guide
- CrowdStrike — September 2026 Patch Tuesday Analysis
- Proofpoint — Multiple State-Aligned Actors Rapidly Adopt BlueMoon
- Google Chrome Releases — September 2026 Stable Channel Security Update
- Cisco — Secure Email Gateway SQL Injection Vulnerability, CVE-2026-76461
- FBI — Iranian Government Cyber Actors and HEAVYGRAM Malware
- Reuters — UK, US and Netherlands Warn About Iran-Linked Spyware
- FortiGuard Labs — Casbaneiro Banking-Trojan Campaign
- Socket — SANDWORM_MODE npm Worm and AI Toolchain Poisoning
- CISA — Known Exploited Vulnerabilities Catalog
- Anthropic — Detecting and Countering Misuse of AI, September 2026

