Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityai-platform-securityidentity-impersonation-fraudvoice-social-engineering

AI-Driven Cybersecurity Threats and Defenses in 2026

Updated 3mo agoFirst seen Nov 5, 20255 sources

Artificial intelligence is rapidly transforming the cybersecurity landscape, with both attackers and defenders leveraging AI to gain an edge. According to Google's Cybersecurity Forecast 2026, AI is now central to cybercrime, enabling adversaries to automate phishing, clone voices for social engineering, and launch sophisticated prompt injection attacks against large language models (LLMs). The rise of AI agents—autonomous systems acting on behalf of users—introduces new identity and access management challenges, as traditional security controls designed for humans are no longer sufficient. Security operations are also evolving, with analysts increasingly relying on AI tools for faster incident response, though this shift brings new oversight and risk management concerns. The criminal underground is developing unrestricted AI models, further lowering the barrier for less advanced threat actors.

The proliferation of AI-generated code and agentic workflows is reshaping software development and supply chain security, as highlighted by Endor Labs' 2025 State of Dependency Management and industry commentary. Studies show that a significant portion of AI-generated code is vulnerable, raising concerns about the security of modern applications. The Model Context Protocol (MCP) is emerging as a standard for enabling AI agents to interact with external tools, but introduces new attack surfaces that require a "Triple Gate Pattern" of defense across the AI, MCP, and API layers. Despite these risks, recent analyses reveal that startups and enterprises are prioritizing productivity and automation over security in their AI investments, often adopting a "build first, secure later" mentality. As AI becomes ubiquitous in both offensive and defensive cyber operations, organizations must adapt their security architectures and practices to address these evolving threats and opportunities.

Share:
AI-Driven Cybersecurity Threats and Defenses in 2026
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Nov 5, 20258mo ago

Google publishes Cybersecurity Forecast 2026 on AI-driven threats

Google released its Cybersecurity Forecast 2026, warning that AI will significantly accelerate cybercrime and reshape both attacker and defender operations. The report highlighted risks including AI-enabled phishing, voice cloning, prompt injection, ransomware, supply-chain attacks, and growing nation-state activity.

Nov 4, 20258mo ago

a16z and Mercury data report highlights lack of explicit AI security tool spending

A spending report based on Mercury fintech platform data and published by Andreessen Horowitz found that startups were primarily buying AI tools for productivity, development, automation, and content generation, with no explicit security tools in the top 50. Commentary in the report coverage said this reflects either a build-first-secure-later mindset or the embedding of security features into broader SaaS and AI platforms.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Organizations
21 linked
Iran InternationalDPRKPeople's Republic of ChinaShinyHuntersRussiaGoogleAnthropicOpenaiAmazonReplitPalo Alto NetworksAppOmniMercuryCursorMicrosoft CorporationOtter.aiSignal MessengerAndreessen HorowitzElevenLabsHappyscribeFreepik
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

AI-Driven Cybersecurity Threats and Defenses in 2026 | Mallory