惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
aimingoo的专栏
aimingoo的专栏
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
D
DataBreaches.Net
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
F
Fortinet All Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
Recent Announcements
Recent Announcements
Jina AI
Jina AI
G
Google Developers Blog
腾讯CDC
博客园_首页
博客园 - 【当耐特】

Business Insights Cybersecurity Blog by Bitdefender

Why Are So Many Security Professionals Keeping Breaches Quiet? Everyone Says Security Consolidation Saves Money. Four Organizations Did the Math The Next MDR Evolution: Digital Sovereignty, Trusted AI, Continuous Protection Frontier AI and the Changing Dynamics of Cybersecurity Bitdefender Threat Debrief | August 2026 Rapidly Rising Risk: AI in the Shadows GravityZone Achieves Top Results in AV-Comparatives Testing When Visibility Becomes the Target: Bitdefender at Black Hat USA 2026 Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core Bitdefender Recognized as a Major Player in the 2026 IDC MarketScape for Worldwide MDR Service for Midmarket What’s New in GravityZone July 2026 (v 6.75) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR Bitdefender Threat Debrief | July 2026 Trust Under Attack: How Deepfakes Are Rewriting Cybercrime Your AI SOC Won’t Catch Ransomware by Itself 2026 Cybersecurity Assessment: The Gap Between Knowing and Doing Your Last Red Team Tested the Wrong Attack MSP Strategic Defense: Why MDR Is the New Security Baseline for MSPs Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices Bitdefender Recognized in the 2026 Gartner® Europe Context: Magic Quadrant™ for Endpoint Protection CISA Mandates Change for Structured, Prioritized Updates and Vulnerability Management Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags What’s New in GravityZone June 2026 (v 6.74) Bitdefender Threat Intelligence: Built for How Security Teams Work Bitdefender Threat Debrief | June 2026 Cut Complexity in Half While Reducing Risk Across Your Endpoint Environment Bitdefender Named a Visionary in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection How Leading Organizations Turn EDR Into Operational Resilience Bitdefender Supports Ferrari Through Cybersecurity Built on Trust Bitdefender at Infosecurity Europe 2026: Staying Ahead of Faster Threats
The New AI Arms Race Starts Before the Attack
Duncan Mills · 2026-09-09 · via Business Insights Cybersecurity Blog by Bitdefender

Artificial intelligence is creating a new attack surface organizations must secure. It’s defined by a collision of forces that make it complex:

  • External AI Threats: Attackers are using AI to increase the speed, volume and personalization of attacks.
  • Internal AI Risk: AI adoption is creating new exposures, connections and data leak potential. This is happening faster than many security teams can govern the risk.

If the response to both developments is simply to generate more alerts after suspicious activity begins, defenders will be trapped in a race they cannot sustainably win. For this reason, the new AI arms race starts well before an attack with AI visibility, control, and the ability to leverage AI to shrink the attack surface.

How Much Is AI Generated Malware Growing?

When it comes to AI generated malware, the trajectory is up and to the right.
From August 2025 through January 2026, Bitdefender Labs tracked more than a 1,000% increase in AI-generated malware samples. This is an early-warning signal that attackers are rapidly testing how AI can help them create, modify and scale malicious code.

ai-malware-growth-bitdefender-labs

What Kind of AI-Enabled Cyberattacks Are Security Teams Seeing?

According to 1,200 IT and cybersecurity professionals surveyed in the Bitdefender 2026 Cybersecurity Assessment, 59% say their organization has experienced social engineering attacks they believe involved AI, while 56% report encountering AI-generated malware-based attacks.
Most strikingly, 70% say they are seeing increasingly sophisticated phishing attacks enabled by AI tools.

As a result, 53% of respondents say AI helps attackers more than defenders.

What Is a Major Challenge Posed by AI-Enabled Attacks?

The central problem is not only whether defenders can detect these attacks, but also whether organizations can continue relying so heavily on detection and response when attacks can be generated, adapted, and launched at machine speed.

How Is AI Expanding the Attack Surface from Within?

AI tool adoption has moved ahead of governance. Security teams are now accountable for an attack surface they may not be able to see clearly, much less control consistently.

Employees are using a wide range of public AI services. Most previously approved tools are now adding AI capabilities. Developers are connecting models to business systems and data through APIs. And let’s not forget about all the potentially sensitive information end-users may be sharing with AI.

Data says IT and Security teams are struggling here: the cybersecurity assessment found that 44.8% of IT and security professionals have only partial visibility into AI use within the organization. And when it comes to 2026 priorities, the number one focus is, “Implementing comprehensive internal AI governance,” according to the research.

Why Are Organizations Pivoting Toward Prevention?

The new AI arms race requires a rebalancing of security priorities, with a pivot toward prevention. A prevention-first strategy moves beyond “How quickly can we detect this attack?” It asks, “How many attack opportunities can we remove before threat actors can take action?”

Detection and response still provide the critical safety net. Prevention reduces how often that net has to catch something and the chance an attack causes material harm.

Internal AI Visibility Is a Starting Point

Looking at internal AI risk, prevention depends on visibility. Organizations cannot reduce an attack surface they cannot see.

Security and IT teams need to understand which AI services are being used, what data and systems they can touch, and which behaviors create the greatest risk. That allows teams to prioritize governance instead of imposing blanket restrictions employees may circumvent.

It also lets organizations use controls they may already have.

Web access policies can address risky services. Hardening policies can reduce exploitable configurations and unnecessary functionality. Web filtering can limit access to public cloud models and Shadow AI.

The objective should not be to stop AI adoption. It should be to make adoption visible, intentional, and safer, without creating another isolated security program that adds more tools, consoles, and operational complexity.

How Can Defenders Leverage AI for Cyber Defense?

Organizations must build AI into their modern security operations center or choose an MDR provider that utilizes AI in the SOC. It helps teams analyze signals, accelerate investigations, automate repetitive work, and respond more quickly. Those capabilities will become increasingly important as threats grow faster and more numerous.

However, the AI arms race will not be won by building faster detection alone. Organizations must also leverage AI-powered tools that can shrink the attack surface and create unique security settings for each user.

Defenders must apply intelligence before an incident begins: identify exposure, reduce privileges, harden environments, govern AI use, and continuously remove potential attack paths. That is how organizations change the equation from racing to contain every AI-enabled attack to denying more of those attacks the opportunity to succeed in the first place.

More: AI-Powered Security Across the Complete Attack Lifecycle