Skip to content
Breachfolio
UPDATED · JULY 2026

AI & Cybersecurity.

How artificial intelligence is reshaping both attack and defense – and what you need to know right now.

HOW IT WORKS

From signal to response – in under a second

What an AI-native defense platform does between the first packet of an attack and the moment it’s contained.

01

Ingest

Logs, packets, endpoint telemetry, identity events. Normalised to a common schema. Time-aligned across every source.

02

Score

A model trained on labelled incidents assigns a confidence score to each chain of events. False-positive rates are calibrated weekly.

03

Decide

Above the threshold, contain. Below it, alert. The boundary is auditable, versioned, and explainable to a regulator.

04

Respond

Isolate the host. Revoke the token. Quarantine the inbox. The response playbook runs autonomously inside a documented blast radius.

Where AI is actually changing the fight

Most vendor claims about "AI-powered security" collapse into one of two categories: statistical anomaly detection that has existed since the 2000s rebranded with a new label, or a genuine large-language-model layer that reads, summarizes, and drafts. The second category is what changed in 2024-2026, and it changed both sides of the fight at the same time, which is why the honest answer to "is AI winning for attackers or defenders" is neither, yet.

How attackers are actually using it

The offensive use cases that show up in real incident reports are unglamorous. Phishing emails no longer have the broken grammar that used to be a reliable tell: a model can localize a lure into fluent Spanish, French, or German in seconds. Reconnaissance that used to take an analyst a day of manual OSINT (organization charts, vendor relationships, employee LinkedIn profiles) can be scraped and summarized in minutes. Voice cloning from a 30-second sample has made "urgent call from the CEO" scams cheap to run at scale. None of this is a new attack technique: it is the same social engineering and phishing playbook that has worked for twenty years, just cheaper and more convincing to produce.

What has not materialized yet, despite the headlines, is autonomous AI malware that discovers and exploits zero-days on its own without a human operator in the loop. Every documented "AI-assisted" intrusion still has a human deciding what to do with the model's output.

How defenders are actually using it

On the blue-team side, the highest-value use case is not detection: it is triage. A mid-size SOC can generate thousands of alerts a day; the median analyst spends most of a shift closing false positives rather than investigating real ones. A model that reads an alert, pulls the relevant logs, and drafts a one-paragraph summary of what probably happened cuts that triage time meaningfully, even when a human still makes the final call. Detection engines that flag behavioral anomalies (a service account authenticating from a new country at 3 a.m.) are a genuine improvement over static signature matching, but they trade false negatives for a different kind of false positive, and tuning that trade-off is still a manual, ongoing job.

Attack vs. defense, side by side

Use caseOffensive valueDefensive value
Content generationFluent phishing lures, deepfake voice/videoAuto-drafted incident summaries and reports
Pattern recognitionFaster target reconnaissance from public dataBehavioral anomaly detection over static rules
AutomationScaling personalized scams cheaplyAlert triage and first-pass log correlation
Current ceilingStill needs a human to weaponize outputStill needs a human to approve containment

What this means if you are not running a SOC

For most people outside a security team, the practical takeaway is narrower than the marketing suggests: assume that any unsolicited message – email, text, or voice call – asking you to move money, click a link, or "verify" a login can no longer be screened by tone or grammar. Verify through a second channel you already trust (call the person back on a known number, not one they just gave you) rather than trusting how polished the request sounds.

  • Treat urgency plus a request for money or credentials as the actual red flag – not typos, which AI has mostly erased.
  • If a "familiar" voice or video asks for something unusual, hang up and call back on a number you already had, not one just given to you.
  • For teams: log every AI-assisted detection decision the same way you would a human one – the audit trail matters more, not less, once a model is in the loop.

Frequently asked questions

Is AI actually being used by cybercriminals?
Yes – AI is already used to write more convincing phishing content, automate reconnaissance, and speed up parts of an attack chain, though most offensive use so far augments existing techniques rather than inventing entirely new ones.
Can AI replace human security analysts?
No, not currently. AI is best used to triage and summarize alerts and speed up investigation, but judgment calls on real incidents still require a human analyst in the loop.
What's the difference between AI-powered threat detection and traditional detection?
Traditional detection relies on known signatures and fixed rules, while AI-powered detection looks for anomalous patterns in behavior, which can catch novel attacks but also produces different kinds of false positives.
Who writes this

Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This page was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us

STAY IN TOUCH

Found something we got wrong, or want to say hello?

We read every message – corrections, tips for a future comparison, or just feedback on this page.

Get in touch