The window between a vulnerability going public and someone weaponizing it has shrunk. And so has our margin for error.
by Tim Leogrande, BSIT, MSCP, Ed.S.
🗓 JUNE 25 2026 • 8 MIN READ
During a recent phone call with a friend who follows the financial markets, he mentioned that he had moved most of his savings into gold and encouraged me to follow suit. Though he sounded a bit agitated, my friend has never been the doomsday-prepper type. What shook him wasn’t an urban legend about aliens living among us, a growing third-world pandemic, or Hollywood’s latest zombie apocalypse flick. It was something far more prosaic.
He was worried because the AI platforms that keep banking, commerce, hospitals, and the power grid running are becoming easier to compromise now that this same technology is writing the malware used to attack those very sectors.
I wasn’t surprised by my friend’s comments because this same issue concerns me. The tools we use to build many Internet applications are just as useful for dismantling them. After all, malware is still software, and it’s hard to overstate the impact AI has already had on the scope, speed, and severity of cyberattacks.
<aside> 💡
Palo Alto Networks reports that attacks against its 80,000 customers quadrupled from 2024 to 2025. AI-enhanced computer viruses that mutate instantly to evade detection are now being generated at an alarming rate. And cyber espionage activities against foreign governments are being increasingly automated. Instead of taking days or hours, threat actors are now exfiltrating data in minutes.
</aside>
My friend is correct that if my bank’s systems are breached through any number of AI-powered attack vectors, my savings could be at risk. A phishing email sent to a branch manager could let hackers into the bank’s back-end systems and walk off with my cash. And even if the bank has excellent cybersecurity, my financial information, and possibly much more, could be stolen through an attack on another organization, such as a medical provider I recently visited, a car rental company I used, or even a newsletter I subscribed to. The number of AI-enabled attack vectors is increasing rapidly, and almost nobody is prepared to defend against all of them.
For years, many organizations could get away with a weak defensive posture because finding and exploiting vulnerabilities required rare expertise. But traditional cybersecurity approaches are no longer sufficient. In the past, you might scramble to patch one new vulnerability over the course of a week. But now you could be addressing several in a single day.
<aside> 💡
According to Moody’s, the window between a vulnerability going public and attackers weaponizing it shrank from more than 700 days in 2020 to just 44 in 2025. This is less time than the average security team requires to deploy a single patch. Disclosure is now a starting gun the burglar and the security guard hear at the same instant, except the burglar now reaches the vault first.
</aside>
AI-enabled cyberwarfare has put governments and large corporations on high alert. The release of two incredibly sophisticated cyber models this spring, the Claude Mythos preview from Anthropic and the comparable GPT-5.5-Cyber from OpenAI shortly thereafter, served as a wake-up call. Anthropic and OpenAI didn’t make these models public, reportedly because they are as skilled as the best human hackers. In an effort to strengthen their own systems, these AI labs have instead given exclusive access to unrestricted versions of their platforms to a select group of government agencies and partner firms.
By using AI to find and fix vulnerabilities before cybercriminals can exploit them, organizations may be able to protect themselves from the impending wave of AI-enabled attacks. Using the Mythos preview model, Anthropic has discovered thousands of defects in the open-source software that powers a large portion of the Internet, many of which had gone unnoticed for years or even decades. In April, Mozilla used Mythos to resolve over 400 Firefox issues, about 20 times as many as it fixes in a normal month. If you've recently noticed a flood of updates to your smartphone apps, office suite, and web browser, it’s likely caused by software companies using AI to scan for problems and to patch systems accordingly.
As comforting as that sounds, these efforts have arrived a bit late to the game. New and freely available tools are making it possible for criminals with little technical expertise to assemble small armies of automated attack bots. And although Google’s, Anthropic’s, and OpenAI’s platforms include safeguards meant to keep them from being used maliciously, there are still several dangers because all three organizations have reported increasingly sophisticated attacks using their technology.
<aside> 💡
For example, AI may have played a role in the May attack on the Canvas learning management system, which disrupted classes at thousands of colleges and universities worldwide. The group that carried out the attack, a well-known hacking ring called ShinyHunters, is notorious for deploying AI in other scams. A few weeks later, Google cybersecurity researchers revealed that this group may have stolen information from more than 100 companies after breaking into an Oracle HR system.
</aside>
There will likely be more frequent and increasingly severe outages and breaches in the near future. Particularly at risk are smaller but vital businesses and institutions that weren’t built for the modern web, like credit unions, municipal government agencies, and power plants because these organizations often run on cumbersome and obsolete code. Naturally, this doesn't mean you should withdraw your savings and buy gold. But it does mean we’ll need to adapt quickly, because GPT-5.5 and Mythos will soon be surpassed by open-source AI platforms.
While bots are strengthening the capabilities of threat actors, they are also weakening the web's defenses. Coding agents are prone to hallucinations and often produce insecure code, while humans, who tend to fetishize fast vibe-coding, don't always take the time to check it. In particular, there have been several disruptions to Amazon's e-commerce systems caused by sloppily written code.
<aside> 💡
The worst-case scenario for the year ahead? The electrical grid going dark across whole regions of the country, telecom carriers being breached, and the banking system buckling as millions of customers watch their balances drain. The most unsettling possibility, though, isn’t any of those. It’s Anthropic’s estimate that a single breach of just one of its roughly 200 partner organizations could impact as many as 100 million people.
</aside>
But none of this requires moving your assets into gold, and most of the countermeasures available to ordinary people are almost insultingly mundane. Reboot your devices regularly so malware that survives only in short-term memory gets washed out. Install system and software updates the same day they drop instead of a month later. Let a password manager generate the kind of long, ugly strings no human would ever attempt to memorize, and treat every unsolicited text message and too-good-to-be-true email as hostile until proven otherwise. And if you want to shrink your attack surface even further, go minimalist with a “thin client” like a Chromebook or simple tablet that stores hardly anything locally and provides a threat actor almost nothing worth stealing.