惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
雷峰网
雷峰网
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 叶小钗
Jina AI
Jina AI
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
量子位
MyScale Blog
MyScale Blog
V
Visual Studio Blog
博客园 - 聂微东
The Cloudflare Blog
Engineering at Meta
Engineering at Meta
小众软件
小众软件
宝玉的分享
宝玉的分享

The Hacker News

SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation 22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023 5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More Why Most AI Deployments Stall After the Demo Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories [Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data The Hacker News The Hacker News Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
The Hacker News
The Hacker News · 2026-06-23 · via The Hacker News

Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death across oceans. At each turn, the distance between the warrior and the wound grew wider, and yet one thing never moved: a human chose the target, and a human struck the blow. For the entire history of conflict, the cyber realm included, the hand has remained on the weapon.

Offensive AI is the moment the weapon learns to aim itself.

For three years, artificial intelligence (AI) has been an extension of the pen. It drafted the phishing email, proposed the exploit, sketched the malicious function, and then, like every tool that came before it, handed the work back to a human to carry out. In 2023, I published a whitepaper at the SANS Technology Institute showing how a person of almost no skill could coax a chatbot into producing malware that strolled past the controls built to stop it. That was the age of the assistant: dangerous, certainly, but still leashed to the operator who held it. Agentic AI severs the leash. It takes the objective and walks the steps itself. This single change, from a tool that drafts to a tool that acts, is reshaping offensive operations faster than the defenses built to catch them, and it cuts in two directions at once. It grants real capability to attackers who never possessed any, and it lends ferocious speed to those who were already deadly.

If your trade is offensive work, this is the ground you now stand upon. The tooling an adversary turns against a target is the tooling you must be capable of turning yourself, and it has marched far beyond chatbots composing prettier phishing. It is worth studying, with clear and unsentimental eyes, what these agents can do today, how they let you operate at a pace that lately seemed impossible, and where they will quietly walk you off a cliff should you follow them with too much faith.

The Gate Has Fallen

Consider the entry-level threat actor, historically limited by a lack of technical expertise. Such individuals can now leverage agents to develop exploits and conduct campaigns autonomously. Technical mastery is no longer a prerequisite; intent and access to capable tools suffice. I refer to this phenomenon as 'script kiddie as a service,' signifying the emergence of sophisticated attacks from previously unskilled actors.

A further implication is that the limitations of unskilled attackers are now defined by the capabilities of their chosen AI models rather than their own expertise. As numerous untrained actors employ similar models in comparable ways, their attack methodologies begin to converge, resulting in a behavioral monoculture. While this increases the volume of competent attacks, it also creates recognizable patterns, such as standardized phishing and exploit chains. Skilled adversaries will adapt beyond these defaults, but the majority will not. Consequently, defenders who understand these default behaviors can better anticipate and mitigate widespread threats.

For experienced practitioners, artificial intelligence does not necessarily enhance skill, but it significantly increases operational speed. Training an agent on established tradecraft enables parallel execution of campaigns, reducing tasks that previously required weeks to mere hours. This dual effect, more attackers at the entry level and accelerated attacks from experts, broadens the overall threat landscape. For those conducting authorized offensive operations, this is now the prevailing standard. Adversaries already utilize these tools, and any engagement that neglects them fails to reflect current threats.

The Hunt Runs Itself

One of the most common examples I often give to people is autonomous social engineering. In this scenario, an attacker deploys an agent to gather publicly available information about a target, such as LinkedIn profiles, press releases, or conference recordings, to construct a detailed profile. This intelligence is then utilized by a second agent, which generates and sends personalized messages, manages responses, and conducts an ongoing conversation, incrementally advancing toward its objective. No human intervention is required in the communication process.

The danger here is not speed; it is the quiet death of the signals we trusted. For years, our phishing defenses leaned on the tells of mass production: the clumsy grammar, the recycled template, the identical mail sent ten thousand times. Those are precisely the tells this arrangement erases. Each message arrives fluent, singular, and grounded in something genuinely true about its mark. Sure, the infrastructure signals endure; things like sender reputation, authentication, and the like still stand watch, but now as defenders, we have to lean on them harder than ever, and how long is it going to be before those defenses break under that pressure? The linguistic and template-level information tells us that so much of our detection, quietly depended upon, is gone.

And it’s not just social engineering. The same automation is overtaking exploitation. As frontier models grow practiced at chaining tool calls and correcting themselves against a living environment, the bar for producing a working exploit is sinking lower with each release. So much so that the federal government is now getting involved and forcing models like Anthropic's Fable 5 to be taken off the market over fears of its capabilities. But this is only the tip of the iceberg. Tying even moderately capable models into a retrieval database of known vulnerabilities, and it will perform its own reconnaissance, judge what a target is likely exposed to, draw the matching exploit from the shelf, and report back like a hound that has caught a scent: I believe this will work, based on these indicators. Shall I run it? Malware is traveling the same road, growing agentic in its own right, and we are already watching agents rewrite existing malware into quieter strains bred to slip past the controls that knew the older form. This started years ago with the introduction of the “Guided Network Access Weapon (GNAW)” which I debuted at the Hackers Teaching Hackers conference.

The Confidence of a False Oracle

All of this makes the agents a very seductive thing to lean upon. They are swift, they run themselves, and they speak with unbroken authority from beginning to end. That last quality is the trap, and to call it lying is to flatter it with intent. The agent is not seeking the truth. It is seeking a finished task and an answer that wears the appearance of being right. It holds no privileged sight into whether a host is truly vulnerable; it matches indicators to a conclusion and delivers that conclusion in the same steady voice, whether the conclusion is sound or hollow. Marry it to a retrieval store of vulnerabilities, and the flaw compounds, for retrieval surfaces what is plausibly related, not what genuinely applies. It does not check the version, nor the configuration, nor whether the service can even be reached. 

Where the Proof Is Made

That problem of judgment is precisely why the place this work occupies matters. The SANS Secure AI Blueprint, authored by SANS Chief AI Officer Rob T. Lee, divides the wider challenge into three tracks: Protect AI, Utilize AI, and Govern AI. Govern produces the policy and the oversight that keep these systems accountable. Protecting hardens the systems an organization actually runs. Utilize is where AI is put to work for offense and defense alike, and offensive operations are its keenest edge.

Leadership hears the words "AI security" and pictures policy binders and a governance committee in a quiet room. Yet Utilize is the only one of the three that yields proof: the actual attacks run against the actual systems, which reveal whether the policy and the hardening hold when they are struck. An organization may write every guideline it pleases and stand up every defense it can purchase, but until someone turns this tooling against its own walls, it does not yet know which of them will hold. A defense is a theory until it makes contact, and the operator is the one who brings it there. That is why the operators are, more and more, the ones who hold the whole program to account.

What the Warrior Is For

Return, then, to where we began. For the whole of human history, the hand stayed on the weapon because the weapon could not be trusted to choose, and that much has not changed. The machine can aim itself now, but it cannot tell you whether the shot should be taken. It will name a target that was never there and ask, in the same untroubled voice it uses when it is right, for permission to fire. Every mechanical part of this craft is passed to the machine. The one part that is not, the judgment to know a true thing from a confident lie and to hold your hand until you are certain, is becoming the whole of the work. The warrior has never stood farther from the wound, and the choice that joins them has never weighed more. The weapon no longer needs a warrior to swing it, but it has never needed a person to decide whether it should be swung at all more than now.

Learn Offensive AI at SANS San Antonio 2026

This August, I will take up these questions in depth during my SEC535: Offensive AI – Attack Tools and Techniques course run at SANS San Antonio 2026. Across three days of hands-on labs, we work the techniques described here from the operator's side of the line: AI-assisted reconnaissance and social engineering, deepfake and voice-cloning attacks, AI-supported vulnerability discovery, and the use of AI in the development and evasion of malware. You will drive the tooling with your own hands and come away with a true sense of its reach, its limits, and the precise points at which it must not be trusted. That is the distance between knowing these attacks exist and being able to carry them out.

The machine will do the aiming. Be the judgment behind the shot.

Register for SANS San Antonio 2026 here.

Note: This article has been expertly written and contributed by Foster Nethercott, SANS SEC535 Course Author.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.