What Are AI-Powered Cyberattacks? Inside Machine-Speed Threats

Sıla Özeren Hacıoğlu | 8 MIN READ

| June 05, 2026

An AI-powered cyberattack, also called an AI hyperattack, is an attack in which AI agents run the entire attack lifecycle on their own: discovering vulnerabilities, developing exploits, abusing credentials, moving laterally, and exfiltrating data. It operates at machine speed and massive parallel scale. What once took skilled operators days or weeks now takes minutes. What once hit a handful of organizations now hits thousands at once.

Is an AI-Powered Cyberattack Real or Still Theoretical?

It is already real. In the February 2026 FortiGate campaign, an AI-powered attack chain compromised 2,516 devices across 106 countries at the same time, running autonomously from start to finish [1].

A threat actor deployed a custom MCP server hosting an LLM. The AI handled backdoor creation, internal infrastructure mapping, autonomous vulnerability assessment, and AI-prioritized execution toward domain admin access. The full chain ran on its own. The only human involvement was reviewing the results afterward.

Figure 1. February 2026 FortiGate Campaign

Figure 1. February 2026 FortiGate Campaign

The discovery side is moving just as fast. Anthropic's Mythos model, the engine behind Project Glasswing, found vulnerabilities across every major operating system and browser. One had survived 27 years in OpenBSD [2]. Mythos did not stop at isolated bugs. It chained independent ones into working exploit sequences.

Figure 2. Claude Mythos Output in Gated Release

Figure 2. Claude Mythos Output in Gated Release

The finding problem is being solved. The fixing problem is not. Fewer than 1% of what Mythos discovered has been patched.

How Fast Can an AI-Enabled Attacker Actually Move Post-Foothold?

An AI-enabled attacker can move from initial foothold to data exfiltration in minutes, with no human in the loop. In the February 2026 FortiGate campaign, the full chain (initial access, credential dumping, and exfiltration) ran autonomously. Attack chains that once required skilled operators now execute in minutes, with LLMs filling the gaps whenever a low-skilled attacker gets stuck.

The speed shows up earlier in the lifecycle too. Mean time-to-exploit (TTE) is the window from a vulnerability's public disclosure to a working, weaponized exploit. It has collapsed year over year:

    • 2018: 2.3 years
    • 2022: 8.6 months
    • 2024: 53 days
    • 2025: 22 days
    • 2026: roughly 24 hours

These figures come from an analysis of +3,500 CVE-exploit pairs across CISA KEV, VulnCheck KEV, and ExploitDB. By 2025, most exploits were already weaponized before public disclosure.

Figure 3. The disclosure-to-weaponization window has shrunk to 24 hours in 2026 [3]

Figure 3. The disclosure-to-weaponization window has shrunk to 24 hours in 2026 [3]

What does this actually mean? It does not mean every organization is breached within an hour of a CVE dropping. It means that the moment a vulnerability goes public, whether through a CVE, a GitHub advisory, or a research post, adversaries have a ready option in their toolkit almost immediately. If one technique fails, they have others on deck.

Why Is Human-Speed Pentesting No Longer Enough?

Because defenders run on calendar speed and attackers run on machine speed. The defensive cycle (gather intel, build a campaign, simulate, mitigate, repeat) takes about four days on a good day. When weaponization happens in hours, a quarterly or even monthly pentest is testing a threat landscape that no longer exists.

Figure 4. Spaghetti Handoff as the bottleneck

Figure 4. Spaghetti Handoff as the bottleneck

The deeper problem is the spaghetti handoff: CTI passes findings to red teams, who hand off to blue teams, who coordinate with vulnerability management and IT. Every handoff adds delay (meetings, tickets, annual leave, competing priorities) widening the gap between attacker speed and defender response. The entire concept of scheduled validation assumes a stable threat landscape, and that assumption is now dead on arrival. A point-in-time pentest tells you what was exploitable last quarter, not whether you're exposed to the advisory that dropped this morning.

What Does Machine-Speed Defense Look Like in Practice?

It rests on three pillars: continuous exposure visibility, hardening to shrink the surface and buy time, and validation to prove what actually works.

Since patching everything inside a 24-hour window is impossible, hardening buys time and validation tells you where to spend it.

Validation has two complementary sides:

  • BAS runs real adversary TTPs against your prevention and detection layers to show what's blocked, what's detected, and what's slipping through your defenses;
  • Autonomous pentesting asks the offensive question of whether an attacker can actually breach you by chaining exposures into paths that reach your crown jewels like Domain Admin.

Both are essential; neither is enough alone.

Figure 5. BAS and Autonomous Pentesting Together

Figure 5. BAS and Autonomous Pentesting Together

Machine-Speed Defense Requires Machine-Speed Validation

Having both pillars is not enough if they run at human speed. To match an attacker who breaches in minutes, the validation loop itself has to run at machine speed.

BAS and autonomous pentesting can be best in class, but as long as the spaghetti handoff sits between them, you are still operating at calendar speed. A human triggers each test, then routes results from team to team, and the window closes before the work is done. The answer is to wire both pillars into an agentic loop: one signal runs the full cycle end to end, with no handoff. Here is what that looks like in practice.

Real Life Use-Case: Emerging Threat Response with an Agentic Workflow

When a new threat signal arrives, an agentic workflow runs the entire response end to end with no manual handoff. A team of specialist agents moves the threat from a raw alert to validated, remediation-ready findings in minutes, across five stages: signal processing, threat analysis, baseline intelligence, validation strategy, and mobilization.

Figure 6. Emerging Threat Response with Agentic Workflow

Figure 6. Emerging Threat Response with Agentic Workflow

Here is how each stage works:

  1. Signal Processing. A signal processing agent receives and processes the incoming alert, for example a CISA advisory like AR25-338A.
  2. Threat Analysis. A CTI analyst agent extracts the TTPs, CVEs, and IoCs from the alert, then invokes threat intelligence to enrich that data.
  3. Baseline Intelligence. A baseliner agent checks the threat's impact against your current baseline, queries your validation platforms (BAS and attack path validation), and flags what your existing coverage has not yet tested.
  4. Validation Strategy. A red teamer agent identifies the scope and TTPs, generates actions for any uncovered techniques, and invokes BAS to test your controls. In parallel, a pentester agent identifies its own scope and TTPs and invokes the autonomous penetration testing tool to test exploitability.
  5. Mobilization Coordination. A mobilizer agent prioritizes findings by business impact, identifies mitigations, auto-deploys the low-risk ones, and opens tickets for the rest. A reporter agent then generates a readiness impact report across all layers.

Every step is traceable and auditable, and you decide where the workflow runs on its own and where it pauses for approval. The result is a cycle that once took four days, now compressed into minutes.

How Do You Measure Your Organization's AI Readiness?

Measure it by one thing: how fast your program can answer "is this vulnerability exploitable in my environment, right now, given what I have deployed?" Not by how many tools you own. Real readiness shows up as signal-driven validation, environment-specific prioritization instead of generic CVSS, and closed-loop remediation that runs without manual handoffs.

The honest test is volume under pressure. When thousands of exploitable findings land on your desk tomorrow, can your program actually process them? This is not hypothetical. Mythos's disclosures are approaching, and over 99% of what it found is still unpatched.

Three metrics tell you where you stand:

  • Time from signal to validated finding. Is it four days, or minutes?
  • Patch latency. How long does a confirmed exposure stay open?
  • Defensive-effectiveness score. Can you produce one continuously, replacing quarterly snapshots with real-time proof?

The baseline is sobering. 83% of cybersecurity programs still show no measurable results. And CVSS makes it worse. When findings jump from hundreds to thousands, a context-free score will not just slow you down. It will break your process, because it cannot tell you what is exploitable in your specific infrastructure.

Where Does Autonomous Penetration Testing Fit in Defending Against AI-Powered Cyberattacks?

Autonomous pentesting is the defender's machine-speed answer to a machine-speed attacker. It reacts to the same signals an AI adversary would, scopes itself, chains real exposures into attack paths, and proves which combinations reach your crown jewels. That lets you close the path before an autonomous adversary walks it.

It plays the offensive half of the validation loop described above. BAS confirms whether your controls would block and detect the attack; autonomous pentesting confirms whether the attack reaches its target at all. Run together inside the agentic workflow, they give you the full picture in minutes: where you're hardened, where you're exposed, and which exposures actually matter.

Here is the part attackers can't replicate. Your one asymmetric advantage is that you know your own topology, and they don't. But that edge only counts if you can act on it at machine speed, on the signal, the moment it lands. Validate at the attacker's tempo and that knowledge becomes a real head start. Keep validating on a calendar and you hand it right back.

Enter Picus Autonomous Penetration Testing

Knowing which vulnerabilities can actually be used against you is the lever that matters, and that is what Autonomous Pentesting proves. Picus Swarm's AI agents map your attack surface, chain real exposures across hosts, and adapt when an exploit fails. Then they apply your environment's context to prove which chains reach crown jewels like Domain Admin, and rank the choke points that break the path. Proven attack paths, full transparency at every step, not a black box.

Figure 7. Agentic Workflow for Proactive Security

Figure 7. Agentic Workflow for Proactive Security

It also doesn't run alone. Inside Picus Platform, autonomous pentesting works alongside BAS as a separate, complementary pillar. One proves what attackers can reach, the other proves what your controls catch. Together they turn a single threat signal into validated, prioritized, remediation-ready findings.

See a real attack path proven in your own environment, from foothold to Domain Admin. Request your free demo.

References

[1] AI-augmented threat actor accesses FortiGate devices at scale: https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/

[2] Assessing Claude Mythos Preview’s cybersecurity capabilities: https://red.anthropic.com/2026/mythos-preview/

[3] From Vulnerability to Exploitation: https://zerodayclock.com/

 
Yes. Automated attacks replay fixed scripts. AI-powered cyberattacks reason and adapt in real time, and they run at machine speed and parallel scale. In the FortiGate campaign the full chain, from initial access to credential dumping to exfiltration, ran autonomously and hit thousands of organizations at once.
The mean time-to-exploit, the window from a vulnerability's disclosure to a working exploit, has collapsed from 2.3 years in 2018 to 56 days in 2024, 23 days in 2025, and roughly 24 hours in 2026. By 2025, most exploits were already weaponized before public disclosure even happened.
It already does. Anthropic's Mythos found a 27-year-old OpenBSD flaw and chained independent bugs into working exploits. AISLE discovered 13 of 14 OpenSSL CVEs in coordinated releases. And XBOW became the top-ranked researcher on HackerOne in 2025, ahead of every human participant.
Because finding is getting radically easier while fixing stays slow. Fewer than 1% of Mythos's findings have been patched. You can't fix everything inside a 10-hour window, so the lever in between is validation: knowing which exposures are actually exploitable in your environment right now.
Move from scheduled to signal-driven validation. Wire your CTI signals, such as new CVEs, advisories, and threat-actor campaigns, directly to autonomous, continuous validation so you learn what's exploitable in your environment before an AI-driven attacker does.

Table of Contents

Ready to start? Request a demo