Prevent Ransomware Blog

When AI Becomes the Hacker: Are Businesses Ready?

Written by Tony Chiappetta | Aug 7, 2026, 8:59:59 AM

Another cyberattack involving AI. But this one is different.

What happens when an attacker no longer needs to manually research your systems, choose an exploit, test it, fail, adjust and try again?

What happens when AI can do much of that work on its own?

That is no longer theoretical.

So what exactly happened?

According to reporting from The Hacker News and research from Palo Alto Networks Unit 42, a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to conduct autonomous cyberattacks. Read the original Hacker News reportRead the Unit 42 researcher receiving an initial instruction through Telegram, the AI agent independently searched for internet-facing systems, evaluated vulnerabilities, downloaded public exploit code and attempted attacks.

When one approach failed, it did not simply stop.

It researched other vulnerabilities, evaluated them based on severity and potential exposure, selected another target and continued.

Unit 42 says the threat actor attempted exploitation against more than 460 targets using autonomous and conventional techniques. Researchers also observed the AI completing targeting analysis that could represent hundreds of hours of human effort in mere minutes. Why should business leaders care?

The concern is not that AI suddenly invented hacking.

The concern is speed, scale and persistence.

Attackers can increasingly automate work that once required skilled people sitting at keyboards. Vulnerability discovery, reconnaissance, exploit selection and attack execution can happen much faster.

The 2026 Verizon Data Breach Investigations Report found that 31% of breaches now begin with vulnerability exploitation. It also reports that ransomware is involved in 48% of breaches and that generative AI is already augmenting multiple attack techniques. Explore Verizon's 2026 DBIR financial stakes remain substantial. IBM's 2025 Cost of a Data Breach Report puts the average global breach cost at $4.44 million, with the U.S. average reaching $10.22 million. Review IBM's breach-cost researcht cost can include operational downtime, lost productivity, incident-response expenses, legal exposure, regulatory obligations, customer disruption and lasting reputation damage.

Can Detect and Respond keep up with AI-speed attacks?

Detection remains important, but relying primarily on detection creates a growing timing problem.

Attackers already abuse stolen credentials, tamper with security tools and use legitimate operating-system utilities to hide their activity.

CISA has specifically warned that living-off-the-land techniques can blend into normal Windows activity and help attackers evade endpoint detection and response products. Read CISA's living-off-the-land guidance add autonomous AI capable of testing alternatives at machine speed.

The question becomes: How much damage can happen before detection produces a response?

Why does Isolation and Containment matter?

Organizations should increasingly design security assuming some attacks will evade detection.

Isolation and Containment changes the objective.

Instead of waiting to identify something as malicious, security policies restrict what applications are permitted to execute and what trusted applications are allowed to do.

That can limit unauthorized execution, restrict attacker movement, reduce the available attack surface and shrink the blast radius before ransomware encryption or credential theft succeeds.

AppGuard is a proven endpoint protection solution with more than 12 years in production focused on prevention through Isolation and Containment. It is designed to complement existing cybersecurity investments rather than depend on identifying every new threat first.

What Should Businesses Do Next?

Business leaders should assume detection will occasionally fail and evaluate what happens next.

Reduce unnecessary endpoint execution freedom. Add prevention layers that operate before malicious actions succeed. Segment critical systems. Review exposed applications and third-party access. Patch internet-facing vulnerabilities quickly. Test what happens if EDR is bypassed or disabled.

Most importantly, test your security architecture against attack speed, not just attack detection.

AI is making attackers faster. Your security strategy cannot depend entirely on humans and detection systems being faster still.

Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should review our August 5th Podcast and schedule time to talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.