Cybersecurity Researchers: AI Has Crossed into the Live Attack Chain

For years, security researchers warned that attackers would use AI to improve existing cybercrime techniques. But according to Check Point Research's recent "AI Security Report 2026," the threat landscape has entered a new phase: AI is no longer just helping attackers; it is beginning to operate inside real-world attacks.

The report describes a shift from AI as a force multiplier to AI as an active component of cyber operations. It documents intrusions in which AI autonomously ran exploitation workflows, generating thousands of commands across dozens of sessions with minimal human direction.

The change matters because it lowers the expertise barrier that traditionally separated advanced attackers from less-skilled criminals. "AI has crossed into the live attack chain," the report states.

The researchers found that AI is now appearing across multiple stages of cyberattacks, including social engineering, malware development, vulnerability research, attacker tool creation, and live intrusion support. The techniques themselves are often familiar. What has changed is the speed and scale at which attackers can execute them.

AI Is Compressing the Cyber Skills Gap

One of the report's most significant findings is that AI is putting sophisticated cyber capabilities within reach of a much wider range of attackers. The researchers said the attackers creating the greatest risks are not necessarily those with the most advanced tools. Instead, the greatest threat comes from groups that can successfully orchestrate AI across multiple stages of an attack.

The report cited a ransomware-as-a-service group known as "The Gentlemen" as an example of how cybercriminals are experimenting with AI. Researchers found that the group used AI to help build its "Glocker" management tool in just three days.

The report also noted an important limitation: AI can accelerate attackers, but human understanding still plays a role. One member of the group warned others that "you still need to understand what you are doing," showing that AI improves attackers' capabilities but does not eliminate the need for expertise.

How Attackers Are Accessing AI Capabilities

Check Point identified three main ways attackers are gaining access to AI capabilities. The most common approach is abusing commercial AI models. Attackers are using widely available tools and attempting to bypass safety controls by breaking malicious requests into smaller, less obvious steps.

The report said attackers are increasingly choosing mainstream AI platforms because they are more capable and accessible than underground alternatives.

Another growing risk is the theft of AI credentials. Check Point highlighted the rise of "LLMjacking," in which criminals use stolen account credentials to access commercial AI services. The report said one campaign, known as Bissa Scanner, stole AI login details from more than 30,000 exposed configuration files.

The third approach involves self-hosted open source models. While these models allow attackers to avoid provider safety controls and logging, the cybersecurity company said many attackers have found them less capable and more difficult to operate than commercial AI tools.

AI Creates a New Security Challenge for Enterprises

The report also highlights a challenge for organizations adopting AI internally. As enterprises deploy more AI applications, they are creating new potential attack surfaces.

Check Point identified risks involving AI models, infrastructure, and applications, while warning that security practices have not always kept pace with adoption. The same AI capabilities that help businesses automate tasks and improve productivity can also introduce new risks if they are poorly secured.

For security teams, the challenge is becoming two-sided. They must defend against attackers using AI while also securing the AI systems their own organizations rely on.

The Next AI Cybersecurity Battle

The rise of AI-powered attacks signals a broader shift in cybersecurity. The question is no longer whether attackers will use AI. According to the report, that transition has already happened.

As Check Point concludes in its report, the incidents observed over the past year represent "a record of what already happened, setting the stage of what's expected to come." The next challenge will be whether defenders can adapt quickly enough as AI becomes more deeply embedded in cyber operations.

The full report is available here on the Check Point site (registration required).

 

Featured

  • Neon blue security locks with a single red highlight

    AI Shifts Cybersecurity Focus from Finding Flaws to Fixing Them

    For decades, one of cybersecurity's most difficult challenges has been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

  • robot hand holding stacks of coins

    Designing AI Systems for Financial Aid

    Financial aid offices have been slow to adopt AI, risking technological stagnation at a critical early student touchpoint. Systematic AI integration can improve student experiences and strengthen institutional positioning.

  • silhouette of business person facing wall of data

    Why AI Strategy Belongs in the President's Office

    Institutions that are succeeding with AI share one thing in common, and it is not a better committee, a larger budget, or a more sophisticated technology stack. It is a president who never handed off the steering wheel.

  • digital brain with network connections

    Microsoft Moving to Internally Developed AI Models in Office Apps

    Microsoft is reportedly using its own in-house artificial intelligence models to handle some workloads in Excel and Outlook, offering new evidence that the company is moving its AI strategy beyond model development and into large-scale cost reduction.