Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitypackage-repository-poisoningai-platform-securitycybersecurity-regulation

AI-Driven Threats and Defenses in Modern Cybersecurity

Updated 3mo agoFirst seen Nov 11, 20253 sources

The rapid integration of artificial intelligence into both attack and defense strategies is reshaping the cybersecurity landscape. AI is now being leveraged by attackers to conduct sophisticated supply chain attacks, as evidenced by a 156% increase in malicious package uploads to open-source repositories and real-world incidents such as the 3CX breach and weaponization of platforms like Hugging Face and GitHub. Traditional security tools are struggling to keep pace, with detection times for breaches increasing and static analysis often failing against polymorphic, context-aware AI-generated malware. In response, organizations are adopting AI-aware security solutions to improve threat detection and response, while regulatory frameworks like the EU AI Act are imposing stricter compliance requirements and significant penalties for violations.

On the defensive side, AI is being used to enhance cloud security by enabling real-time threat detection, risk anticipation, and automated response, which has contributed to a reduction in average breach costs. The fusion of DDI (DNS, DHCP, and IP address management) data with AI platforms is also transforming network security, allowing for predictive, autonomous defense mechanisms that close visibility gaps in complex, hybrid environments. These advancements are critical as enterprises face increasingly automated and adaptive threats that exploit the seams between network and security operations.

Share:
AI-Driven Threats and Defenses in Modern Cybersecurity
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Nov 11, 20257mo ago

AI-enabled supply chain attacks surge 156% over the past year

The reference reports that AI-enabled supply chain attacks increased by 156% in the past year, marking a major escalation in the threat landscape. This is presented as a current trend rather than a single dated incident, so the publication date is used.

EU AI Act imposes new compliance requirements and penalties

The article says regulatory frameworks such as the EU AI Act are introducing strict compliance obligations and heavy penalties for organizations. No exact effective date is stated in the reference content.

IBM reports average breach identification time of 276 days

The reference states that IBM reported an average of 276 days to identify a breach, underscoring the difficulty organizations face in detecting modern attacks. The specific report date is not included in the content provided.

Wondershare RepairIt vulnerabilities cited in AI supply chain threat landscape

The article points to vulnerabilities in Wondershare RepairIt as another concrete incident illustrating the growing sophistication of supply chain threats. No precise disclosure or exploitation date is given in the provided content.

Solana Web3.js npm library compromise highlighted as key supply chain incident

A compromise involving the Solana Web3.js npm library is identified as a significant software supply chain event demonstrating the impact of modern AI-enabled attacks. The reference does not provide a specific date for the compromise.

NullBulge attacks target Hugging Face and GitHub repositories

The article cites attacks by the NullBulge group against Hugging Face and GitHub repositories as notable examples of AI-enabled supply chain activity. No specific event date is provided in the reference, so the date is inferred from the article's publication date.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Threat actors
1 linked
Organizations
15 linked
Hugging FaceMITREInternational Business MachinesSonatypeNetflixAnthropicSolanaMicrosoft CorporationGitHubEUPytorch3cxWondershareNullBulgeGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.